Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections to the configured DingTalk webhooks.
History

Thu, 12 Jun 2025 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins dingtalk
CPEs cpe:2.3:a:jenkins:dingtalk:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins dingtalk

Thu, 15 May 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 14 May 2025 20:45:00 +0000

Type Values Removed Values Added
Description Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections to the configured DingTalk webhooks.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published: 2025-05-14T20:35:57.422Z

Updated: 2025-05-15T13:24:31.285Z

Reserved: 2025-05-13T12:21:13.541Z

Link: CVE-2025-47888

cve-icon Vulnrichment

Updated: 2025-05-15T13:24:22.533Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-14T21:15:59.747

Modified: 2025-06-12T13:26:33.590

Link: CVE-2025-47888

cve-icon Redhat

No data.