CVE-2023-35142

Severity
8.1HIGH
EPSS
0.1%
top 74.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 14

Description

Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

3
CVEList
CVE-2023-35142: Jenkins Checkmarx Plugin 20222023-06-14
OSV
SSL/TLS certificate validation disabled by default in Jenkins Checkmarx Plugin2023-06-14
GHSA
SSL/TLS certificate validation disabled by default in Jenkins Checkmarx Plugin2023-06-14

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2023-06-142023-06-14
Red Hat
jenkins-2-plugins: checkmarx: SSL/TLS certificate validation disabled by default in Checkmarx Plugin2023-06-14
CVE-2023-35142 (HIGH CVSS 8.1) | Jenkins Checkmarx Plugin 2022.4.3 a | cvebase.io