CVE-2018-1000149

MEDIUM5.6EPSS 0.07%

Jenkins Ansible Plugin man in the middle vulnerability

Published: 5/13/2022Modified: 12/3/2024
Also known as:GHSA-322x-jv5h-cvjh

Description

A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in `AbstractAnsibleInvocation.java`, `AnsibleAdHocCommandBuilder.java`, `AnsibleAdHocCommandInvocationTest.java`, `AnsibleContext.java`, `AnsibleJobDslExtension.java`, `AnsiblePlaybookBuilder.java`, `AnsiblePlaybookStep.java` that disables host key verification by default. Ansible Plugin 1.0 now enables host key verification by default, adding options allowing users to opt out.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.6CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

References (3)