CVE-2022-28142
Java vulnerability analysis and mitigation

Overview

Jenkins Proxmox Plugin 0.6.0 and earlier contains a security vulnerability related to SSL/TLS certificate validation. The vulnerability was discovered and disclosed on March 29, 2022, affecting the Jenkins Proxmox Plugin versions up to and including 0.6.0. This vulnerability is tracked as CVE-2022-28142 (Jenkins Advisory, CVE Mitre).

Technical details

The vulnerability occurs when the plugin is configured to ignore SSL/TLS issues, which results in disabling SSL/TLS certificate validation globally for the entire Jenkins controller Java Virtual Machine (JVM). This configuration affects the security of all SSL/TLS connections made by the Jenkins controller, not just those related to the Proxmox Plugin. The vulnerability has been assigned a Medium severity CVSS rating (Jenkins Advisory).

Impact

When exploited, this vulnerability compromises the security of all SSL/TLS connections made by the Jenkins controller, potentially exposing the system to man-in-the-middle attacks and other SSL/TLS-related security issues. The global nature of the certificate validation disable means that it affects not just the Proxmox Plugin's connections, but all SSL/TLS connections made by the Jenkins controller (Jenkins Advisory).

Mitigation and workarounds

The vulnerability was fixed in Proxmox Plugin version 0.7.0, which no longer disables SSL/TLS certificate validation for the entire Jenkins controller JVM. Users are advised to upgrade to version 0.7.0 or later to address this security issue (Jenkins Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-26866HIGH8.8
  • JavaJava
  • org.apache.hugegraph:hg-pd-core
NoYesDec 12, 2025
CVE-2025-66474HIGH8.7
  • JavaJava
  • org.xwiki.rendering:xwiki-rendering-xml
NoYesDec 10, 2025
CVE-2025-66473HIGH8.7
  • JavaJava
  • org.xwiki.platform:xwiki-platform-rest-server
NoYesDec 10, 2025
CVE-2025-67505HIGH8.4
  • JavaJava
  • com.okta.sdk:okta-sdk-root
NoYesDec 10, 2025
CVE-2025-14518MEDIUM5.3
  • JavaJava
  • tech.powerjob:powerjob-common
NoNoDec 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management