Red Hat Bugzilla – Bug 1501815
CVE-2017-1000402 jenkins-pugin-swarm: Swarm Plugin Client bundled vulnerable version of the commons-httpclient library (SECURITY-597)
Last modified: 2018-06-29 18:28:59 EDT
Swarm Plugin Client bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. External References: https://jenkins.io/security/advisory/2017-10-11/
swarm plugin not included in latest openshift3/jenkins-2-rhel7 image. Check using this package: https://access.redhat.com/downloads/content/jenkins-2-plugins/3.7.1502412812-1.el7/noarch/fd431d51/package