CVE-2019-16561: High severity jenkins websphere deployer vulnerability
Published Dec 17, 2019
·Updated
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for the entire Jenkins master JVM.
Affected Software
2 affected components
Jenkins Websphere Deployer Jenkins<=1.6.1
maven/org.jenkins-ci.plugins:websphere-deployer<=1.6.1
Event History
Dec 17, 2019
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:03 PM
Frequently Asked Questions
1
What is the vulnerability ID for this Jenkins vulnerability?
The vulnerability ID for this Jenkins vulnerability is CVE-2019-16561.
2
What is the severity of CVE-2019-16561?
The severity of CVE-2019-16561 is high with a severity value of 7.1.
3
How does Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allow SSL/TLS validation to be disabled?
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for the entire Jenkins master JVM.
4
What is the affected software for CVE-2019-16561?
The affected software for CVE-2019-16561 is Jenkins WebSphere Deployer Plugin 1.6.1 and earlier.
5
How can I fix CVE-2019-16561?
To fix CVE-2019-16561, update Jenkins WebSphere Deployer Plugin to a version later than 1.6.1.