Jenkins ElectricFlow Plugin globally and unconditionally disabled SSL/TLS certificate validation
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Dec 5, 2023
Package
Affected versions
<= 1.1.6
Patched versions
1.1.7
Description
Published by the National Vulnerability Database
Jun 11, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Oct 26, 2023
Last updated
Dec 5, 2023
CloudBees CD Plugin unconditionally disabled SSL/TLS certificate validation for the entire Jenkins controller JVM during the deployment/publication of an application.
CloudBees CD Plugin no longer does that. Instead, the existing opt-in option to ignore SSL/TLS errors is used during deployment for the specific connection.
This issue was caused by an incomplete fix for SECURITY-937.
References