Insecure digital certificates In org.jenkins-ci.plugins:ansible
Description
Jenkins Ansible Plugin man in the middle vulnerability
A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, AnsibleAdHocCommandInvocationTest.java, AnsibleContext.java, AnsibleJobDslExtension.java, AnsiblePlaybookBuilder.java, AnsiblePlaybookStep.java that disables host key verification by default. Ansible Plugin 1.0 now enables host key verification by default, adding options allowing users to opt out.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 1.0 |
Aliases
1. 2. 3. 4.
References
1. 2.