QID 996995

Date Published: 2024-01-31

QID 996995: Java (Maven) Security Update for com.checkmarx.jenkins:checkmarx (GHSA-rr3p-5fcf-v5m3)

Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-rr3p-5fcf-v5m3 for updates and patch information.
    Vendor References

    CVEs related to QID 996995

    Software Advisories
    Advisory ID Software Component Link
    GHSA-rr3p-5fcf-v5m3 com.checkmarx.jenkins:checkmarx URL Logo github.com/advisories/GHSA-rr3p-5fcf-v5m3