CVE-2020-2146

CVSS v3.1 7.4 (High)
74% Progress
CVSS v2.0 5.8 (Medium)
58% Progress
EPSS 0.13 % (48th)
0.13% Progress
Affected Products 1
Advisories 2

Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.

Weaknesses
CWE-347
Improper Verification of Cryptographic Signature
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2020-03-09 16:15:13
(4 years ago)
Updated Date
2023-10-25 18:16:32
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Mac for Jenkins 1.1.0 and prior versions cpe:2.3:a:jenkins:mac::*:*:*:*:jenkins <= 1.1.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...