Vulnerability Database
Blog
FAQ
Docs
CVE-2019-10314
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2019-10314
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10314.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-10314
Aliases
GHSA-3qf7-9xhj-qcfj
Published
2019-04-30T13:29:05Z
Modified
2024-09-03T02:22:06.642020Z
Severity
5.9 (Medium)
CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Calculator
Summary
[none]
Details
Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
References
https://jenkins.io/security/advisory/2019-04-30/#SECURITY-936
http://www.openwall.com/lists/oss-security/2019/04/30/5
http://www.securityfocus.com/bid/108159
Affected packages
Git
/
github.com/jenkinsci/koji-plugin
Affected ranges
Type
GIT
Repo
https://github.com/jenkinsci/koji-plugin
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Last affected
0f5fd00e02722d5236ce2398e1ef4d8e356e540c
Affected versions
jenkins-koji-0.*
jenkins-koji-0.1.1
jenkins-koji-plugin-0.*
jenkins-koji-plugin-0.1
jenkins-koji-plugin-0.1.2
jenkins-koji-plugin-0.1.3
jenkins-koji-plugin-0.2
koji-0.*
koji-0.3
koji-jenkins-plugin-0.*
koji-jenkins-plugin-0.1
CVE-2019-10314 - OSV