PT-2020-15399 · Jenkins · Jenkins Amazon Ec2 Plugin+1
Raihaan Shouhell
·
Published
2020-05-06
·
Updated
2023-10-25
·
CVE-2020-2185
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Jenkins Amazon EC2 Plugin versions 1.50.1 and earlier
Description
The issue concerns a lack of SSH host key validation when connecting agents, which could enable man-in-the-middle attacks to intercept connections to build agents. This could potentially allow unauthorized access or manipulation of data.
Recommendations
For Jenkins Amazon EC2 Plugin versions 1.50.1 and earlier, update to version 1.50.2 or later, which provides strategies for performing host key validation and assistance for migrating to a more secure strategy.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Amazon Ec2 Plugin