CVE-2019-10446: High severity jenkins cadence vmanager plugin vulnerability
Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10446?
CVE-2019-10446 has a High severity rating due to its potential to expose sensitive data through insecure SSL/TLS connections.
How do I fix CVE-2019-10446?
To fix CVE-2019-10446, upgrade the Jenkins Cadence vManager Plugin to version 2.7.1 or later to re-enable SSL/TLS and hostname verification.
What are the potential impacts of CVE-2019-10446?
The potential impacts of CVE-2019-10446 include man-in-the-middle attacks and the exposure of sensitive information due to disabled SSL/TLS and hostname verification.
Which versions of Jenkins Cadence vManager are affected by CVE-2019-10446?
Jenkins Cadence vManager Plugin versions 2.7.0 and earlier are affected by CVE-2019-10446.
Is there a workaround for CVE-2019-10446?
There is no official workaround for CVE-2019-10446; upgrading to a secure version is the recommended action.