Codefresh Integration Plugin unconditionally disables SSL/TLS certificate validation for the entire Jenkins controller JVM.
As of publication of this advisory, there is no fix.
{ "github_reviewed_at": "2023-03-03T23:08:42Z", "severity": "MODERATE", "nvd_published_at": "2019-08-07T15:15:00Z", "cwe_ids": [ "CWE-295" ], "github_reviewed": true }