[MAVEN:GHSA-W86J-99WG-R29F] Jenkins TraceTronic ECU-TEST Plugin Man in the middle vulnerability

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows attackers to impersonate any service that Jenkins connects to.

Package Affected Version
pkg:maven/de.tracetronic.jenkins.plugins/ecutest <= 2.3
ID
MAVEN:GHSA-W86J-99WG-R29F
Severity
high
URL
https://github.com/advisories/GHSA-w86j-99wg-r29f
Published
2022-05-14T02:57:12
(2 years ago)
Modified
2024-01-09T21:28:42
(8 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/de.tracetronic.jenkins.plugins/ecutest de.tracetronic.jenkins.plugins ecutest <= 2.3
Fixed pkg:maven/de.tracetronic.jenkins.plugins/ecutest de.tracetronic.jenkins.plugins ecutest = 2.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...