CVE-2017-1000402: Jenkins Swarm

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks.

Affected products

  • Jenkins Swarm: up to and including 3.4

Published 2018-01-26. Last modified 2026-06-17.