HomeDefault status
unknown
Any version
affected
Description
Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections to the configured DingTalk webhooks.
Product status
Any version
References
www.jenkins.io/security/advisory/2025-05-14/ (Jenkins Security Advisory 2025-05-14)