PT-2020-15357 · Jenkins · Jenkins Mabl Plugin+1

Nils Emmerich

·

Published

2020-03-09

·

Updated

2023-10-25

·

CVE-2020-2146

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Mac Plugin versions 1.1.0 and earlier
Description The issue concerns the lack of SSH host key validation when connecting agents created by the plugin, which could enable man-in-the-middle attacks. This allows an attacker to intercept connections to build agents.
Recommendations For Jenkins Mac Plugin versions 1.1.0 and earlier, update to version 1.2.0 or later, which includes SSH host key validation when connecting to agents.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2020-2146
GHSA-RV9G-67F7-GRQ7

Affected Products

Jenkins
Jenkins Mabl Plugin