GHSA-2j5w-cwc3-8hxw
GitHub Security Advisory
Improper Certificate Validation in Jenkins Spira Importer Plugin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.
Affected Packages
Maven
com.inflectra.spiratest.plugins:inflectra-spira-integration
Affected versions:
0
(fixed in 3.2.4)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.