CVE-2023-37948 – org.jenkins-ci.plugins:oracle-cloud-infrastructure-compute
Package
Manager: maven
Name: org.jenkins-ci.plugins:oracle-cloud-infrastructure-compute
Vulnerable Version: >=0 <1.0.17
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00056 pctl0.17547
Details
Jenkins Oracle Cloud Infrastructure Compute Plugin missing SSH host key validation Jenkins Oracle Cloud Infrastructure Compute Plugin 1.0.16 and earlier does not perform SSH host key validation when connecting to OCI clouds. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections to OCI clouds. Oracle Cloud Infrastructure Compute Plugin 1.0.17 provides strategies for performing host key validation for administrators to select the one that meets their security needs.
Metadata
Created: 2023-07-12T18:30:38Z
Modified: 2023-07-12T22:31:07Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-j54r-w587-95q7/GHSA-j54r-w587-95q7.json
CWE IDs: ["CWE-20"]
Alternative ID: GHSA-j54r-w587-95q7
Finding: F184
Auto approve: 1