GHSA-r3mm-v4x7-2phm
GitHub Security Advisory
Jenkins NeuVector Vulnerability Scanner Plugin disables SSL/TLS certificate and hostname validation
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server.
Affected Packages
Maven
io.jenkins.plugins:neuvector-vulnerability-scanner
Affected versions:
0
(last affected: 1.22)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 24, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.