Jenkins Eggplant Runner Plugin protection mechanism disabled
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Oct 29, 2025 
          to the GitHub Advisory Database
          •
          Updated Oct 29, 2025 
      
  
Package
Affected versions
<= 0.0.1.301.v963cffe8ddb
  Patched versions
None
  Description
        Published by the National Vulnerability Database
      Oct 29, 2025 
    
  
        Published to the GitHub Advisory Database
      Oct 29, 2025 
    
  
        Reviewed
      Oct 29, 2025 
    
  
        Last updated
      Oct 29, 2025 
    
  
Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property
jdk.http.auth.tunneling.disabledSchemesto an empty value as part of applying a proxy configuration.This disables a protection mechanism of the Java runtime addressing CVE-2016-5597.
As of publication of this advisory, there is no fix.
References