QID 996956
Date Published: 2024-01-29
QID 996956: Java (Maven) Security Update for org.jenkins-ci.main:maven-plugin (GHSA-qhxw-54m9-6wwc)
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qhxw-54m9-6wwc for updates and patch information.
Vendor References
- GHSA-qhxw-54m9-6wwc -
github.com/advisories/GHSA-qhxw-54m9-6wwc
CVEs related to QID 996956
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qhxw-54m9-6wwc | org.jenkins-ci.main:maven-plugin |
|