CVE-2024-28161: Medium severity jenkins delphix vulnerability
Published Mar 6, 2024
·Updated
In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled by default.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins:delphix=3.0.1
3.0.2
Jenkins Delphix Jenkins=3.0.1
Event History
Mar 6, 2024
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
Affected Software
Advisory Published
via GitHub·06:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-28161?
CVE-2024-28161 is classified as a high severity vulnerability due to the impact on SSL/TLS certificate validation.
2
How do I fix CVE-2024-28161?
To fix CVE-2024-28161, upgrade the Jenkins Delphix Plugin to version 3.0.2 or later.
3
What systems are affected by CVE-2024-28161?
CVE-2024-28161 affects Jenkins Delphix Plugin version 3.0.1.
4
What are the potential risks of CVE-2024-28161?
The risks of CVE-2024-28161 include exposure to man-in-the-middle attacks due to disabled SSL/TLS certificate validation.
5
Who is primarily impacted by CVE-2024-28161?
Administrators using the Jenkins Delphix Plugin version 3.0.1 are primarily impacted by CVE-2024-28161.