QID 995830
Date Published: 2023-11-06
QID 995830: Java (Maven) Security Update for org.jenkins-ci.plugins:bumblebee (GHSA-qgp8-h5cp-r75r)
Jenkins Bumblebee HP ALM Plugin unconditionally disabled SSL/TLS certificate validation for connections to the HP ALM service.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qgp8-h5cp-r75r for updates and patch information.
Vendor References
- GHSA-qgp8-h5cp-r75r -
github.com/advisories/GHSA-qgp8-h5cp-r75r
CVEs related to QID 995830
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qgp8-h5cp-r75r | org.jenkins-ci.plugins:bumblebee |
|