First published: Wed Oct 16 2019(Updated: )
Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Cadence Vmanager | <=2.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10446 has a High severity rating due to its potential to expose sensitive data through insecure SSL/TLS connections.
To fix CVE-2019-10446, upgrade the Jenkins Cadence vManager Plugin to version 2.7.1 or later to re-enable SSL/TLS and hostname verification.
The potential impacts of CVE-2019-10446 include man-in-the-middle attacks and the exposure of sensitive information due to disabled SSL/TLS and hostname verification.
Jenkins Cadence vManager Plugin versions 2.7.0 and earlier are affected by CVE-2019-10446.
There is no official workaround for CVE-2019-10446; upgrading to a secure version is the recommended action.