[MAVEN:GHSA-QHXW-54M9-6WWC] MitM on Jenkins Maven Plugin

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.

Package Affected Version
pkg:maven/org.jenkins-ci.main/maven-plugin < 3.0
Package Fixed Version
pkg:maven/org.jenkins-ci.main/maven-plugin = 3.0
ID
MAVEN:GHSA-QHXW-54M9-6WWC
Severity
moderate
URL
https://github.com/advisories/GHSA-qhxw-54m9-6wwc
Published
2022-05-14T03:45:43
(2 years ago)
Modified
2023-12-21T23:12:59
(9 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.main/maven-plugin org.jenkins-ci.main maven-plugin < 3.0
Fixed pkg:maven/org.jenkins-ci.main/maven-plugin org.jenkins-ci.main maven-plugin = 3.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...