CVE-2023-30516
12.04.2023, 18:15
Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries, resulting in job configurations using Image Tag Parameters that were created before 2.0 having SSL/TLS certificate validation disabled by default.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | image_tag_parameter | 𝑥 < 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration