CVE-2017-1000402

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-1000402
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-1000402.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-1000402
Aliases
Published
2018-01-26T02:29:01Z
Modified
2024-10-12T02:25:13.177014Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks.

References

Affected packages

Git / github.com/jenkinsci/swarm-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/swarm-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

swarm-plugin-1.*

swarm-plugin-1.10
swarm-plugin-1.11
swarm-plugin-1.12
swarm-plugin-1.13
swarm-plugin-1.14
swarm-plugin-1.15
swarm-plugin-1.16
swarm-plugin-1.17
swarm-plugin-1.18
swarm-plugin-1.19
swarm-plugin-1.20
swarm-plugin-1.21
swarm-plugin-1.22
swarm-plugin-1.23
swarm-plugin-1.24
swarm-plugin-1.25
swarm-plugin-1.26
swarm-plugin-1.5
swarm-plugin-1.6
swarm-plugin-1.7
swarm-plugin-1.8
swarm-plugin-1.9

swarm-plugin-2.*

swarm-plugin-2.0
swarm-plugin-2.1
swarm-plugin-2.2
swarm-plugin-2.3

swarm-plugin-3.*

swarm-plugin-3.0
swarm-plugin-3.1
swarm-plugin-3.2
swarm-plugin-3.3
swarm-plugin-3.4