Description
Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connections to HP ALM.
Remediation
References
https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1481
Related Vulnerabilities
CVE-2018-10912 Vulnerability in maven package org.keycloak:keycloak-model-infinispan
CVE-2019-0205 Vulnerability in maven package org.webjars.npm:thrift
CVE-2018-5382 Vulnerability in maven package org.bouncycastle:bcprov-jdk14
CVE-2021-30179 Vulnerability in maven package org.apache.dubbo:dubbo
CVE-2022-23618 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore