Inadequate SSL/TLS Certificate Validation in Jenkins Image Tag Parameter Plugin
CVE-2023-30516
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 12 April 2023
Summary
The Jenkins Image Tag Parameter Plugin version 2.0 has introduced a configurational flaw concerning SSL/TLS certificate validation. Specifically, it allows connections to Docker registries without adequate verification of SSL/TLS certificates. This misconfiguration means that job setups utilizing Image Tag Parameters—established prior to version 2.0—default to having SSL/TLS certificate validation turned off. As a result, there is an increased risk of man-in-the-middle attacks, exposing sensitive data to potential interception and misuse. Users must ensure that SSL/TLS validation is manually re-enabled to safeguard against these vulnerabilities when configuring Docker jobs.
Affected Version(s)
Jenkins Image Tag Parameter Plugin 0 <= 2.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved