First published: Thu Apr 05 2018(Updated: )
A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by default.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Vsphere | <=2.16 | |
maven/org.jenkins-ci.plugins:vsphere-cloud | <=2.16 | 2.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.