Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8qq-2p5p-rg44

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.6

Описание

Missing SSH host key validation in Jenkins Amazon EC2 Plugin

Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not use SSH host key validation when connecting to agents. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections to build agents.

Jenkins Amazon EC2 Plugin 1.50.2 provides strategies for performing host key validation for administrators to select the one that meets their security needs. It includes assistance for administrators to migrate to a new, more secure strategy. For more information see the plugin documentation.

Пакеты

Наименование

org.jenkins-ci.plugins:ec2

maven
Затронутые версииВерсия исправления

<= 1.50.1

1.50.2

EPSS

Процентиль: 28%
0.001
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-300

Связанные уязвимости

CVSS3: 5.6
nvd
почти 6 лет назад

Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the-middle attacks.

EPSS

Процентиль: 28%
0.001
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-300