GHSA-rv9g-67f7-grq7
Dashboard / Vulnerabilities / GHSA-rv9g-67f7-grq7
Summary: Missing SSH host key validation in Mac Plugin
Details: Mac Plugin 1.1.0 and earlier does not use SSH host key validation when connecting to Mac Cloud host launched by the plugin. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections to build agents. Mac Plugin 1.2.0 validates SSH host keys when connecting to agents.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2146, https://github.com/jenkinsci/mac-plugin/commit/ba1a8206c7ef990d37498e5abdf210990ef046b5, https://github.com/jenkinsci/mac-plugin, https://jenkins.io/security/advisory/2020-03-09/#SECURITY-1692, http://www.openwall.com/lists/oss-security/2020/03/09/1
Affected packages
Package
Name: fr.edf.jenkins.plugins:mac
Purl: pkg:maven/fr.edf.jenkins.plugins/mac
Affected ranges
Type: ECOSYSTEM
Events:
