Lucene search

K

Ec2 Security Vulnerabilities

cve
cve

CVE-2017-1000502

Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be launched. Configuration of these agents now requires the 'Run Scripts' permission typically only...

8.8CVSS

8.7AI Score

0.002EPSS

2022-10-03 04:23 PM
28
cve
cve

CVE-2020-2187

Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle...

5.6CVSS

5.5AI Score

0.001EPSS

2020-05-06 01:15 PM
37
cve
cve

CVE-2020-2188

A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in...

4.3CVSS

4.4AI Score

0.001EPSS

2020-05-06 01:15 PM
34
cve
cve

CVE-2020-2186

A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision...

4.3CVSS

4.5AI Score

0.001EPSS

2020-05-06 01:15 PM
35
cve
cve

CVE-2020-2185

Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the-middle...

5.6CVSS

5.5AI Score

0.001EPSS

2020-05-06 01:15 PM
39
cve
cve

CVE-2020-2091

A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained through another...

8.1CVSS

7.9AI Score

0.001EPSS

2020-01-15 04:15 PM
41
5
cve
cve

CVE-2020-2090

A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained through another...

8.8CVSS

8.6AI Score

0.001EPSS

2020-01-15 04:15 PM
42
cve
cve

CVE-2019-10364

Jenkins Amazon EC2 Plugin 1.43 and earlier wrote the beginning of private keys to the Jenkins system...

5.5CVSS

5.4AI Score

0.0004EPSS

2019-07-31 01:15 PM
30
cve
cve

CVE-2012-5817

Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to...

7.4CVSS

7.3AI Score

0.001EPSS

2012-11-04 10:55 PM
35