[JENKINS:SECURITY-1528] Lack of SSL/TLS certificate and hostname validation in `ec2`

Severity Medium
Affected Packages 2
Fixed Packages 2
CVEs 1

ec2 connects to Windows agents via HTTPS.

ec2 1.50.1 and earlier unconditionally accepts self-signed HTTPS certificates and does not perform hostname validation when connecting to Windows agents.
This lack of validation could be abused using a man-in-the-middle attack to intercept these connections to build agents.

ec2 1.50.2 by default no longer accepts self-signed HTTPS certificates and performs hostname validation.
A new configuration option allows restoring the previous, unsafe behavior.
For more information see https://github.com/jenkinsci/ec2-plugin/#securing-the-connection-to-windows-amis[the plugin documentation].

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/ec2 <= 1.50.1
pkg:github/jenkinsci/ec2-plugin <= 1.50.1
ID
JENKINS:SECURITY-1528
Severity
medium
Published
2020-05-06T00:00:00
(4 years ago)
Modified
2020-05-06T00:00:00
(4 years ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository ec2 repository https://github.com/jenkinsci/ec2-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/ec2 org.jenkins-ci.plugins ec2 <= 1.50.1
Fixed pkg:maven/org.jenkins-ci.plugins/ec2 org.jenkins-ci.plugins ec2 = 1.50.2
Affected pkg:github/jenkinsci/ec2-plugin jenkinsci ec2-plugin <= 1.50.1
Fixed pkg:github/jenkinsci/ec2-plugin jenkinsci ec2-plugin = 1.50.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...