Description
Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9Attack Vector: Network
Complexity: High
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages3 packages
🔴Vulnerability Details
3CVEListCVE-2023-35142: Jenkins Checkmarx Plugin 2022↗2023-06-14 ▶ OSVSSL/TLS certificate validation disabled by default in Jenkins Checkmarx Plugin↗2023-06-14 ▶ GHSASSL/TLS certificate validation disabled by default in Jenkins Checkmarx Plugin↗2023-06-14 ▶ 📋Vendor Advisories
2JenkinsJenkins Security Advisory 2023-06-14↗2023-06-14 ▶ Red Hatjenkins-2-plugins: checkmarx: SSL/TLS certificate validation disabled by default in Checkmarx Plugin↗2023-06-14 ▶