Description
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.
Remediation
References
https://jenkins.io/security/advisory/2017-10-11/
Related Vulnerabilities
CVE-2017-12645 Vulnerability in maven package com.liferay.portal:com.liferay.portal.impl
CVE-2023-49395 Vulnerability in maven package com.jfinal:jfinal
CVE-2023-25572 Vulnerability in maven package org.webjars.npm:react-admin
CVE-2018-1000143 Vulnerability in maven package org.jenkins-ci.plugins:ghprb
CVE-2017-1000104 Vulnerability in maven package org.jenkins-ci.plugins:config-file-provider