jenkins-2-plugins: checkmarx: SSL/TLS certificate validation disabled by default in Checkmarx Plugin
Published Jun 14, 2023
8.1
HIGHCVSS 3.1
EPSS 0.78%
Description
Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.
Affected products
-
- Version 0StatusaffectedConstraints<=2022.4.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Jenkins Project | Jenkins Checkmarx Plugin | unaffected |
|
No data.
Cryostat 2
jenkins-2-plugins
Not affected
Node HealthCheck Operator
jenkins-2-plugins
Not affected
OpenShift Developer Tools and Services
jenkins-2-plugins
Affected
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins
Affected
Red Hat OpenShift Container Platform 4
jenkins-2-plugins
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Cryostat 2 | jenkins-2-plugins | Not affected | n/a |
| Node HealthCheck Operator | jenkins-2-plugins | Not affected | n/a |
| OpenShift Developer Tools and Services | jenkins-2-plugins | Affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins-2-plugins | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The Jenkins Checkmarx Plugin is not shipped in any of the Red Hat products. Hence, closing as not a bug.
References (7)
- http://www.openwall.com/lists/oss-security/2023/06/14/5 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-35142 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2215077 Issue Tracking
- https://github.com/advisories/GHSA-rr3p-5fcf-v5m3 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-35142
- https://www.cve.org/CVERecord?id=CVE-2023-35142
- https://www.jenkins.io/security/advisory/2023-06-14/#SECURITY-2870 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2023/06/14/5 | Mailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2023-35142 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2215077 | Issue Tracking | |
| https://github.com/advisories/GHSA-rr3p-5fcf-v5m3 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-35142 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-35142 | ||
| https://www.jenkins.io/security/advisory/2023-06-14/#SECURITY-2870 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.