CVE-2023-37948

CVSS v3.1 3.7 (Low)
37% Progress
EPSS 0.06 % (28th)
0.06% Progress
Affected Products 1
Advisories 2

Jenkins Oracle Cloud Infrastructure Compute Plugin 1.0.16 and earlier does not validate SSH host keys when connecting OCI clouds, enabling man-in-the-middle attacks.

Weaknesses
CWE-20
Improper Input Validation
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2023-07-12 16:15:13
(14 months ago)
Updated Date
2023-07-20 14:15:47
(14 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Cloud Infrastructure Compute for Jenkins prior 1.0.17 version cpe:2.3:a:jenkins:cloud_infrastructure_compute::*:*:*:*:jenkins < 1.0.17
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...