Loading HuntDB...

GHSA-qgp8-h5cp-r75r

GitHub Security Advisory

Jenkins Bumblebee HP ALM Plugin unconditionally disabled SSL/TLS certificate validation

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Bumblebee HP ALM Plugin unconditionally disabled SSL/TLS certificate validation for connections to the HP ALM service.

Bumblebee HP ALM Plugin no longer does that. Instead, it now allows users to opt out of certificate validation.

Affected Packages

Maven org.jenkins-ci.plugins:bumblebee
Affected versions: 0 (fixed in 4.1.4)

Related CVEs

Key Information

GHSA ID
GHSA-qgp8-h5cp-r75r
Published
May 24, 2022 4:58 PM
Last Modified
October 26, 2023 11:06 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:bumblebee
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.