CVE-2020-2185
MEDIUM5.6EPSS 0.10%Missing SSH host key validation in Jenkins Amazon EC2 Plugin
發布日:2022/5/24修改日:2024/2/16
描述
Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not use SSH host key validation when connecting to agents. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections to build agents. Jenkins Amazon EC2 Plugin 1.50.2 provides strategies for performing host key validation for administrators to select the one that meets their security needs. It includes assistance for administrators to migrate to a new, more secure strategy. For more information see [the plugin documentation](https://github.com/jenkinsci/ec2-plugin/#securing-the-connection-to-unix-amis).
受影響套件(1)
- Maven/org.jenkins-ci.plugins:ec2from 0, < 1.50.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.6 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L |
參考連結(5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-2185
- PATCHhttps://github.com/jenkinsci/ec2-plugin
- WEBhttps://github.com/jenkinsci/ec2-plugin/commit/4c9f03ae202e4730fd54eda40771fa4d3873e358
- WEBhttps://jenkins.io/security/advisory/2020-05-06/#SECURITY-381
- WEBhttp://www.openwall.com/lists/oss-security/2020/05/06/3