CVE-2019-10382: Medium severity jenkins vmware lab manager slaves vulnerability
Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10382?
The severity of CVE-2019-10382 is medium with a severity value of 6.5.
How does CVE-2019-10382 affect Jenkins VMware Lab Manager Slaves Plugin?
CVE-2019-10382 affects Jenkins VMware Lab Manager Slaves Plugin version 0.2.8 and earlier by disabling SSL/TLS and hostname verification globally for the Jenkins master JVM.
How can I fix CVE-2019-10382 in Jenkins VMware Lab Manager Slaves Plugin?
To fix CVE-2019-10382 in Jenkins VMware Lab Manager Slaves Plugin, update to a version later than 0.2.8 that enables SSL/TLS and hostname verification.
Are there any references related to CVE-2019-10382?
Yes, you can find more information about CVE-2019-10382 at the following references: [http://www.openwall.com/lists/oss-security/2019/08/07/1](http://www.openwall.com/lists/oss-security/2019/08/07/1) and [https://jenkins.io/security/advisory/2019-08-07/#SECURITY-1376](https://jenkins.io/security/advisory/2019-08-07/#SECURITY-1376).
What is the CWE ID for CVE-2019-10382?
The CWE ID for CVE-2019-10382 is 295.