cbcvebase.
CVE-2023-30517
published 2023-04-12

CVE-2023-30517: Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server.

Affected

16 ranges
VendorProductVersion rangeFixed in
jenkinsassembla_merge_request_builder_plugin
jenkinsazure_key_vault_plugin
jenkinsconsul_kv_builder_plugin
jenkinsdelinea_secret_server_platform_plugin
jenkinsfogbugz_plugin
jenkinsimage_tag_parameter_plugin
jenkinskubernetes_plugin
jenkinslack_of_authentication_mechanism_in_fogbugz_plugin
jenkinslack_of_authentication_mechanism_in_turboscript_plugin
jenkinslucene-search_plugin
jenkinsneuvector_vulnerability_scanner<= 1.22
jenkinsquay.io_trigger_plugin
jenkinsreport_portal_plugin
jenkinsthycotic_devops_secrets_vault_plugin
jenkinsturboscript_plugin
jenkins_projectjenkins_neuvector_vulnerability_scanner_plugin<= 1.22