Description
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. This library is widely used as a transitive dependency in Jenkins plugins. The fix for CVE-2012-6153 was backported to the version of commons-httpclient that is bundled in core and made available to plugins.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP TripAdvisor Review Slider SQL Injection (10.7)
WordPress Plugin Elementor Website Builder Security Bypass (1.7.12)
WordPress 4.0.x Cross-Site Request Forgery (4.0 - 4.0.25)
ATutor Other Vulnerability (CVE-2014-9752)
Moodle Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-21809)