CVE-2018-1000149

MEDIUM5.6EPSS 0.07%

Jenkins Ansible Plugin man in the middle vulnerability

發布日:2022/5/13修改日:2024/12/3

描述

A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in `AbstractAnsibleInvocation.java`, `AnsibleAdHocCommandBuilder.java`, `AnsibleAdHocCommandInvocationTest.java`, `AnsibleContext.java`, `AnsibleJobDslExtension.java`, `AnsiblePlaybookBuilder.java`, `AnsiblePlaybookStep.java` that disables host key verification by default. Ansible Plugin 1.0 now enables host key verification by default, adding options allowing users to opt out.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.6CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

參考連結(3)