cbcvebase.
CVE-2022-38666
published 2022-11-15

CVE-2022-38666: Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for several…

high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for several features.

Affected

23 ranges
VendorProductVersion rangeFixed in
jenkinsassociated_files_plugin
jenkinsbart_plugin
jenkinscccc_plugin
jenkinscluster_statistics_plugin
jenkinsconfig_rotator_plugin
jenkinsdelete_log_plugin
jenkinsjapex_plugin
jenkinsjunit_plugin
jenkinsnaginator_plugin
jenkinsns-nd_integration_performance_publisher<= 4.8.0.146
jenkinsns-nd_integration_performance_publisher_plugin
jenkinspipeline_utility_steps_plugin
jenkinsregistry_notification_plugin
jenkinsreverse_proxy_auth_plugin
jenkinsscript_security_plugin
jenkinssourcemonitor_plugin
jenkinssupport_core_plugin
jenkinsurls_in_the_plugin
jenkinsviolations_plugin
jenkinsxml_linter_plugin
jenkinsxp-dev_plugin
jenkins_projectjenkins_ns-nd_integration_performance_publisher_pluginunspecified – 4.8.0.146
linuxlinux_kernel>= 0 < 5.4.0-224.2445.4.0-224.244

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.8HIGH