CVE-2023-35142
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2023-35142 is a vulnerability affecting the Jenkins Checkmarx Plugin version 2022.4.3 and older. By default, this plugin disables SSL/TLS validation for connections to the Checkmarx server, leaving these communications open to man-in-the-middle attacks, data interception, and unauthorized access. This issue poses a significant risk to organizations using the Jenkins Checkmarx Plugin for security scanning, as it undermines the very encryption measures intended to protect their data. To mitigate this threat, it is recommended that users upgrade to the latest version of the plugin or configure SSL/TLS validation manually.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.