First published: Fri Jan 26 2018(Updated: )
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Maven | <=2.17 | |
maven/org.jenkins-ci.main:maven-plugin | <3.0 | 3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000397 is classified as a medium severity vulnerability.
To fix CVE-2017-1000397, upgrade the Jenkins Maven Plugin to version 3.0 or later.
Versions of Jenkins Maven Plugin up to and including 2.17 are affected by CVE-2017-1000397.
CVE-2017-1000397 exposes users to man-in-the-middle attacks due to improper SSL certificate verification.
No, Jenkins Maven Plugin version 3.0 does not have a dependency on the vulnerable commons-httpclient library.