Description
Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/11/21/1
https://jenkins.io/security/advisory/2019-11-21/#SECURITY-1584
Related Vulnerabilities
CVE-2019-10362 Vulnerability in maven package io.jenkins:configuration-as-code
CVE-2023-45133 Vulnerability in maven package org.webjars.npm:babel__traverse
CVE-2019-10339 Vulnerability in maven package org.jenkins-ci.plugins:jx-resources
CVE-2021-28163 Vulnerability in maven package org.eclipse.jetty:jetty-deploy
CVE-2022-36364 Vulnerability in maven package org.apache.calcite.avatica:avatica-core