Description
A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by default.
Remediation
References
https://jenkins.io/security/advisory/2018-03-26/#SECURITY-504
Related Vulnerabilities
CVE-2012-3353 Vulnerability in maven package org.apache.sling:org.apache.sling.jcr.contentloader
CVE-2014-3630 Vulnerability in maven package com.typesafe.akka:akka-http-xml-experimental_2.11
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http_2.13
CVE-2016-5016 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2021-37580 Vulnerability in maven package org.apache.shenyu:shenyu-admin