Lucene search

K
osvGoogleOSV:GHSA-345P-PW5Q-G98V
HistoryMay 24, 2022 - 5:01 p.m.

Jenkins Google Compute Engine Plugin does not verify SSH host keys when connecting agents created by the plugin

2022-05-2417:01:41
Google
osv.dev
10

0.001 Low

EPSS

Percentile

47.9%

Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks. Google Compute Engine Plugin 4.2.0 verifies SSH host keys before executing any commands on agents.

0.001 Low

EPSS

Percentile

47.9%

Related for OSV:GHSA-345P-PW5Q-G98V