QID 997313
Date Published: 2024-02-20
QID 997313: Java (Maven) Security Update for com.inedo.buildmaster:inedo-buildmaster (GHSA-hrr3-7r5v-vxx5)
A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java, BuildMasterApi.java that allows attackers to impersonate any service that Jenkins connects to.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hrr3-7r5v-vxx5 for updates and patch information.
Vendor References
- GHSA-hrr3-7r5v-vxx5 -
github.com/advisories/GHSA-hrr3-7r5v-vxx5
CVEs related to QID 997313
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hrr3-7r5v-vxx5 | com.inedo.buildmaster:inedo-buildmaster |
|