Inadequate SSL/TLS Certificate Validation in Jenkins Image Tag Parameter Plugin
CVE-2023-30516

6.5MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
12 April 2023

Summary

The Jenkins Image Tag Parameter Plugin version 2.0 has introduced a configurational flaw concerning SSL/TLS certificate validation. Specifically, it allows connections to Docker registries without adequate verification of SSL/TLS certificates. This misconfiguration means that job setups utilizing Image Tag Parameters—established prior to version 2.0—default to having SSL/TLS certificate validation turned off. As a result, there is an increased risk of man-in-the-middle attacks, exposing sensitive data to potential interception and misuse. Users must ensure that SSL/TLS validation is manually re-enabled to safeguard against these vulnerabilities when configuring Docker jobs.

Affected Version(s)

Jenkins Image Tag Parameter Plugin 0 <= 2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.