Jenkins Image Tag Parameter Plugin improperly introduces option to opt out of SSL/TLS certificate validation
Moderate severity
GitHub Reviewed
Published
Apr 12, 2023
to the GitHub Advisory Database
•
Updated Apr 21, 2023
Package
Affected versions
<= 2.0
Patched versions
None
Description
Published by the National Vulnerability Database
Apr 12, 2023
Published to the GitHub Advisory Database
Apr 12, 2023
Reviewed
Apr 12, 2023
Last updated
Apr 21, 2023
Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries.
Job configurations using Image Tag Parameters that were created before 2.0 will have SSL/TLS certificate validation disabled by default.
References