First published: Wed Apr 12 2023(Updated: )
Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server.
Credit: jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Neuvector Vulnerability Scanner | <=1.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Jenkins NeuVector vulnerability is CVE-2023-30517.
The title of this Jenkins NeuVector vulnerability is 'Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation'.
The severity of CVE-2023-30517 is medium with a CVSS score of 5.3.
The affected software for this vulnerability is Jenkins NeuVector Vulnerability Scanner Plugin version 1.22 and earlier.
To fix the Jenkins NeuVector vulnerability, update the NeuVector Vulnerability Scanner Plugin to version 1.23 or later.