Loading HuntDB...

GHSA-38jc-2rwx-qgxr

GitHub Security Advisory

Jenkins Image Tag Parameter Plugin improperly introduces option to opt out of SSL/TLS certificate validation

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries.

Job configurations using Image Tag Parameters that were created before 2.0 will have SSL/TLS certificate validation disabled by default.

Affected Packages

Maven org.jenkins-ci.plugins:image-tag-parameter
Affected versions: 0 (last affected: 2.0)

Related CVEs

Key Information

GHSA ID
GHSA-38jc-2rwx-qgxr
Published
April 12, 2023 6:30 PM
Last Modified
April 12, 2023 10:19 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:image-tag-parameter
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.