GHSA-pxp5-g66h-wpv2

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-pxp5-g66h-wpv2/GHSA-pxp5-g66h-wpv2.json
Aliases
  • CVE-2022-41244
Published
2022-09-22T00:00:29Z
Modified
2023-03-18T05:49:41.003114Z
Details

Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections.

References

Affected packages

Maven / org.jenkins-ci.plugins:view26

org.jenkins-ci.plugins:view26

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0

Affected versions

1.*

1.0.2
1.0.3
1.0.4
1.0.7

Database specific

{
    "last_known_affected_version_range": "<= 1.0.7"
}