cbcvebase.
CVE-2024-28162
published 2024-03-06

CVE-2024-28162: In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data…

PriorityP419medium4.2CVSS 3.1
AVNACHPRNUIRSUCLILAN
EPSS
0.34%
25.9th percentile
In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections fails to take effect until Jenkins is restarted when switching from disabled validation to enabled validation.

Affected

13 ranges
VendorProductVersion rangeFixed in
jenkinsappspider_plugin
jenkinsbitbucket_branch_source_plugin
jenkinsbuild_monitor_view_plugin
jenkinsdelphix>= 3.0.1 < 3.1.13.1.1
jenkinsdelphix_plugin
jenkinsgitbucket_plugin
jenkinshtml_publisher_plugin
jenkinsimproper_input_sanitization_in_html_publisher_plugin
jenkinsmq_notifier_plugin
jenkinsowasp_dependency-check_plugin
jenkinssubversion_partial_release_manager_plugin
jenkinstls_certificate_validation_in_delphix_plugin
jenkins_projectjenkins_delphix_plugin3.0.1 – 3.1.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.