Description
Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries, resulting in job configurations using Image Tag Parameters that were created before 2.0 having SSL/TLS certificate validation disabled by default.
Published: 2023-04-12
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-1171 Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries, resulting in job configurations using Image Tag Parameters that were created before 2.0 having SSL/TLS certificate validation disabled by default.
Github GHSA Github GHSA GHSA-38jc-2rwx-qgxr Jenkins Image Tag Parameter Plugin improperly introduces option to opt out of SSL/TLS certificate validation
History

Fri, 07 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Jenkins Image Tag Parameter
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2025-02-07T19:02:14.079Z

Reserved: 2023-04-12T08:40:40.603Z

Link: CVE-2023-30516

cve-icon Vulnrichment

Updated: 2024-08-02T14:28:51.096Z

cve-icon NVD

Status : Modified

Published: 2023-04-12T18:15:09.027

Modified: 2025-02-07T19:15:23.320

Link: CVE-2023-30516

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses