First published: Wed Aug 07 2019(Updated: )
Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Vmware Lab Manager Slaves | <=0.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-10382 is medium with a severity value of 6.5.
CVE-2019-10382 affects Jenkins VMware Lab Manager Slaves Plugin version 0.2.8 and earlier by disabling SSL/TLS and hostname verification globally for the Jenkins master JVM.
To fix CVE-2019-10382 in Jenkins VMware Lab Manager Slaves Plugin, update to a version later than 0.2.8 that enables SSL/TLS and hostname verification.
Yes, you can find more information about CVE-2019-10382 at the following references: [http://www.openwall.com/lists/oss-security/2019/08/07/1](http://www.openwall.com/lists/oss-security/2019/08/07/1) and [https://jenkins.io/security/advisory/2019-08-07/#SECURITY-1376](https://jenkins.io/security/advisory/2019-08-07/#SECURITY-1376).
The CWE ID for CVE-2019-10382 is 295.