GHSA-q8qq-2p5p-rg44

    Dashboard / Vulnerabilities / GHSA-q8qq-2p5p-rg44

    GHSA-q8qq-2p5p-rg44

    Published: 24 May 2022Last Modified: 16 Feb 2024
    Aliases:

    Summary: Missing SSH host key validation in Jenkins Amazon EC2 Plugin

    Details: Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not use SSH host key validation when connecting to agents. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections to build agents. Jenkins Amazon EC2 Plugin 1.50.2 provides strategies for performing host key validation for administrators to select the one that meets their security needs. It includes assistance for administrators to migrate to a new, more secure strategy. For more information see [the plugin documentation](https://github.com/jenkinsci/ec2-plugin/#securing-the-connection-to-unix-amis).

    Affected packages

    Package

    Name: org.jenkins-ci.plugins:ec2

    Purl: pkg:maven/org.jenkins-ci.plugins/ec2

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.50.2

    Affected versions

    1.11

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-q8qq-2p5p-rg44 | CVE-DB