Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j54r-w587-95q7

Опубликовано: 12 июл. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

Jenkins Oracle Cloud Infrastructure Compute Plugin missing SSH host key validation

Jenkins Oracle Cloud Infrastructure Compute Plugin 1.0.16 and earlier does not perform SSH host key validation when connecting to OCI clouds.

This lack of validation could be abused using a man-in-the-middle attack to intercept these connections to OCI clouds.

Oracle Cloud Infrastructure Compute Plugin 1.0.17 provides strategies for performing host key validation for administrators to select the one that meets their security needs.

Пакеты

Наименование

org.jenkins-ci.plugins:oracle-cloud-infrastructure-compute

maven
Затронутые версииВерсия исправления

< 1.0.17

1.0.17

EPSS

Процентиль: 23%
0.00076
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 3.7
nvd
больше 2 лет назад

Jenkins Oracle Cloud Infrastructure Compute Plugin 1.0.16 and earlier does not validate SSH host keys when connecting OCI clouds, enabling man-in-the-middle attacks.

EPSS

Процентиль: 23%
0.00076
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-20