A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by default.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://jenkins.io/security/advisory/2018-03-26/#SECURITY-504 | vendor advisory |