Vulnerabilities
Vulnerable Software
Jenkins:  >> Amazon Ec2  >> 1.22  Security Vulnerabilities
Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the-middle attacks.
CVSS Score
5.6
EPSS Score
0.001
Published
2020-05-06
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision instances.
CVSS Score
4.3
EPSS Score
0.005
Published
2020-05-06
Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle attacks.
CVSS Score
5.6
EPSS Score
0.0
Published
2020-05-06
A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
CVSS Score
4.3
EPSS Score
0.0
Published
2020-05-06
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained through another method.
CVSS Score
8.8
EPSS Score
0.001
Published
2020-01-15
A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained through another method.
CVSS Score
8.1
EPSS Score
0.002
Published
2020-01-15


Contact Us

Shodan ® - All rights reserved