Description
Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the-middle attacks.
Remediation
References
https://jenkins.io/security/advisory/2020-05-06/#SECURITY-381
http://www.openwall.com/lists/oss-security/2020/05/06/3
Related Vulnerabilities
CVE-2022-24723 Vulnerability in npm package urijs
CVE-2023-45648 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2019-7619 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2020-2128 Vulnerability in maven package com.catalogic.ecxjenkins:catalogic-ecx
CVE-2021-33036 Vulnerability in maven package org.apache.hadoop:hadoop-yarn-server-common