GHSA-j54r-w587-95q7

Suggest an improvement
Source
https://github.com/advisories/GHSA-j54r-w587-95q7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-j54r-w587-95q7/GHSA-j54r-w587-95q7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j54r-w587-95q7
Aliases
  • CVE-2023-37948
Published
2023-07-12T18:30:38Z
Modified
2024-02-16T07:56:25.445841Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Jenkins Oracle Cloud Infrastructure Compute Plugin missing SSH host key validation
Details

Jenkins Oracle Cloud Infrastructure Compute Plugin 1.0.16 and earlier does not perform SSH host key validation when connecting to OCI clouds.

This lack of validation could be abused using a man-in-the-middle attack to intercept these connections to OCI clouds.

Oracle Cloud Infrastructure Compute Plugin 1.0.17 provides strategies for performing host key validation for administrators to select the one that meets their security needs.

Database specific
{
    "cwe_ids": [
        "CWE-20"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-12T22:31:07Z",
    "nvd_published_at": "2023-07-12T16:15:13Z",
    "severity": "MODERATE"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:oracle-cloud-infrastructure-compute

Package

Name
org.jenkins-ci.plugins:oracle-cloud-infrastructure-compute
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/oracle-cloud-infrastructure-compute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.17

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-j54r-w587-95q7/GHSA-j54r-w587-95q7.json"