QID 996059
Date Published: 2023-11-27
QID 996059: Java (Maven) Security Update for org.jenkins-ci.plugins:electricflow (GHSA-xmqv-pfw7-qmj7)
CloudBees CD Plugin unconditionally disabled SSL/TLS certificate validation for the entire Jenkins controller JVM during the deployment/publication of an application.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xmqv-pfw7-qmj7 for updates and patch information.
Vendor References
- GHSA-xmqv-pfw7-qmj7 -
github.com/advisories/GHSA-xmqv-pfw7-qmj7
CVEs related to QID 996059
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xmqv-pfw7-qmj7 | org.jenkins-ci.plugins:electricflow |
|