CVE-2018-1000151

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2018-1000151
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000151.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-1000151
Aliases
Published
2018-04-05T13:29:00Z
Modified
2024-09-03T02:01:19.704963Z
Severity
  • 5.6 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by default.

References

Affected packages

Git / github.com/jenkinsci/vsphere-cloud-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/vsphere-cloud-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

vsphere-cloud-0.*

vsphere-cloud-0.10
vsphere-cloud-0.2
vsphere-cloud-0.3
vsphere-cloud-0.4
vsphere-cloud-0.5
vsphere-cloud-0.6
vsphere-cloud-0.7
vsphere-cloud-0.8
vsphere-cloud-0.9

vsphere-cloud-1.*

vsphere-cloud-1.0.1
vsphere-cloud-1.0.2
vsphere-cloud-1.1.0
vsphere-cloud-1.1.1
vsphere-cloud-1.1.10
vsphere-cloud-1.1.11
vsphere-cloud-1.1.12
vsphere-cloud-1.1.2
vsphere-cloud-1.1.3
vsphere-cloud-1.1.4
vsphere-cloud-1.1.5
vsphere-cloud-1.1.6
vsphere-cloud-1.1.7
vsphere-cloud-1.1.8
vsphere-cloud-1.1.9

vsphere-cloud-2.*

vsphere-cloud-2.0
vsphere-cloud-2.10
vsphere-cloud-2.11
vsphere-cloud-2.12
vsphere-cloud-2.13
vsphere-cloud-2.14
vsphere-cloud-2.15
vsphere-cloud-2.16
vsphere-cloud-2.2
vsphere-cloud-2.3
vsphere-cloud-2.4
vsphere-cloud-2.5
vsphere-cloud-2.6
vsphere-cloud-2.7
vsphere-cloud-2.8
vsphere-cloud-2.9