Jenkins NS-ND Integration Performance Publisher Plugin Vulnerability - Jenkins
CVE-2022-45391
7.5HIGH
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 15 November 2022
Summary
The Jenkins NS-ND Integration Performance Publisher Plugin prior to version 4.8.0.144 disables SSL/TLS certificate and hostname validation across the Jenkins controller JVM. This lack of validation can expose systems to potential man-in-the-middle attacks, as the plugin can accept unverified or malicious certificate connections. Without proper certificate validation, sensitive data may be intercepted or compromised, posing significant security risks for users relying on this integration.
Affected Version(s)
Jenkins NS-ND Integration Performance Publisher Plugin <= 4.8.0.143
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved