CVE-2019-10334

CVSS v3 Score
6.5
Medium
CVSS v2 Score
5.8
Medium

Vulnerability Description

Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM when MultipartUtility.java is used to upload files.

CVSS:6.5(Medium)

A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.

CVSS:6.5(Medium)

Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.

CVSS:6.5(Medium)

Google Chrome caches TLS sessions before certificate validation occurs.

CVSS:6.5(Medium)

The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certif...

CVSS:6.5(Medium)

In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).

CVSS:6.5(Medium)

curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or fa...