A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java, BuildMasterApi.java that allows attackers to impersonate any service that Jenkins connects to.
References
Link | Resource |
---|---|
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-935 | Vendor Advisory |
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-935 | Vendor Advisory |
Configurations
History
21 Nov 2024, 03:57
Type | Values Removed | Values Added |
---|---|---|
References | () https://jenkins.io/security/advisory/2018-07-30/#SECURITY-935 - Vendor Advisory |
Information
Published : 2018-08-01 13:29
Updated : 2024-11-21 03:57
NVD link : CVE-2018-1999035
Mitre link : CVE-2018-1999035
CVE.ORG link : CVE-2018-1999035
JSON object : View
Products Affected
jenkins
- inedo_buildmaster
CWE
CWE-295
Improper Certificate Validation