QID 996995
Date Published: 2024-01-31
QID 996995: Java (Maven) Security Update for com.checkmarx.jenkins:checkmarx (GHSA-rr3p-5fcf-v5m3)
Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-rr3p-5fcf-v5m3 for updates and patch information.
Vendor References
- GHSA-rr3p-5fcf-v5m3 -
github.com/advisories/GHSA-rr3p-5fcf-v5m3
CVEs related to QID 996995
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rr3p-5fcf-v5m3 | com.checkmarx.jenkins:checkmarx |
|