Description
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.
Remediation
References
https://jenkins.io/security/advisory/2017-10-11/
Related Vulnerabilities
CVE-2019-1003036 Vulnerability in maven package org.jenkins-ci.plugins:azure-vm-agents
CVE-2020-11023 Vulnerability in npm package jquery
CVE-2019-1003034 Vulnerability in maven package org.jenkins-ci.plugins:job-dsl
CVE-2023-24457 Vulnerability in maven package org.jenkins-ci.plugins:keycloak
CVE-2012-0394 Vulnerability in maven package org.apache.struts:struts2-core