Jenkins NS-ND Integration Performance Publisher Plugin Vulnerability - Jenkins
CVE-2022-45391
7.5HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 15 November 2022
What is CVE-2022-45391?
The Jenkins NS-ND Integration Performance Publisher Plugin prior to version 4.8.0.144 disables SSL/TLS certificate and hostname validation across the Jenkins controller JVM. This lack of validation can expose systems to potential man-in-the-middle attacks, as the plugin can accept unverified or malicious certificate connections. Without proper certificate validation, sensitive data may be intercepted or compromised, posing significant security risks for users relying on this integration.
Affected Version(s)
Jenkins NS-ND Integration Performance Publisher Plugin <= 4.8.0.143