CVE-2017-1000397: Jenkins Maven

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.

Affected products

  • Jenkins Maven: up to and including 2.17

Published 2018-01-26. Last modified 2026-06-17.