Vulnerability in Checkmarx Plugin for Jenkins
CVE-2023-35142
8.1HIGH
What is CVE-2023-35142?
The Jenkins Checkmarx Plugin prior to version 2022.4.4 is vulnerable due to disabling SSL/TLS validation by default for connections to the Checkmarx server, potentially allowing man-in-the-middle (MitM) attacks. This can expose sensitive data and compromise security protocols, putting users at risk if an attacker intercepts the communication.
Affected Version(s)
Jenkins Checkmarx Plugin 0 <= 2022.4.3