CVE-2019-10314: Medium severity jenkins vulnerability
Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
Other sources
Jenkins Koji Plugin unconditionally disables SSL/TLS certificate validation for the entire Jenkins controller JVM.
As of publication of this advisory, there is no fix.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10314?
CVE-2019-10314 is considered a high severity vulnerability due to the unconditionally disabled SSL/TLS certificate validation on the Jenkins master JVM.
How do I fix CVE-2019-10314?
As of now, there is no fix available for CVE-2019-10314, so users should take precautionary measures to secure their Jenkins environments.
What versions of Jenkins Koji are affected by CVE-2019-10314?
CVE-2019-10314 affects all versions of Jenkins Koji Plugin up to and including version 0.3.
What are the consequences of CVE-2019-10314?
The consequences of CVE-2019-10314 include potential exposure to man-in-the-middle attacks due to the lack of SSL/TLS and hostname verification.
Is there a workaround for CVE-2019-10314?
There are currently no official workarounds for CVE-2019-10314, but users may consider disabling the Koji Plugin until a resolution is available.