Description
Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle attacks.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/05/06/3
https://jenkins.io/security/advisory/2020-05-06/#SECURITY-1528
Related Vulnerabilities
CVE-2019-9737 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md
CVE-2023-46493 Vulnerability in npm package @evershop/evershop
CVE-2019-10355 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2019-10403 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-17187 Vulnerability in maven package org.apache.qpid:proton-j