Description
The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-1999-0450)
WordPress 4.6.x Multiple Vulnerabilities (4.6 - 4.6.26)
WordPress Plugin Quiz Maker Multiple SQL Injection Vulnerabilities (6.2.0.8)
Oracle JRE CVE-2024-21144 Vulnerability (CVE-2024-21144)
Jenkins Resource Management Errors Vulnerability (CVE-2014-3661)