First published: Tue Dec 17 2019(Updated: )
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for the entire Jenkins master JVM.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Websphere Deployer | <=1.6.1 | |
maven/org.jenkins-ci.plugins:websphere-deployer | <=1.6.1 | |
<=1.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Jenkins vulnerability is CVE-2019-16561.
The severity of CVE-2019-16561 is high with a severity value of 7.1.
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for the entire Jenkins master JVM.
The affected software for CVE-2019-16561 is Jenkins WebSphere Deployer Plugin 1.6.1 and earlier.
To fix CVE-2019-16561, update Jenkins WebSphere Deployer Plugin to a version later than 1.6.1.