Description
Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.
Remediation
References
https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1580
http://www.openwall.com/lists/oss-security/2019/12/17/1
Related Vulnerabilities
CVE-2016-3087 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2022-43430 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test
CVE-2023-25194 Vulnerability in maven package org.apache.kafka:kafka-clients
CVE-2022-42735 Vulnerability in maven package org.apache.shenyu:shenyu-admin
CVE-2014-0227 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core