Loading HuntDB...

GHSA-c89c-pvm7-33wj

GitHub Security Advisory

Lack of SSL/TLS certificate and hostname validation in Amazon EC2 Plugin

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Amazon EC2 Plugin connects to Windows agents via HTTPS.

Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed HTTPS certificates and does not perform hostname validation when connecting to Windows agents. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections to build agents.

Amazon EC2 Plugin 1.50.2 by default no longer accepts self-signed HTTPS certificates and performs hostname validation. A new configuration option allows restoring the previous, unsafe behavior. For more information see [the plugin documentation](https://github.com/jenkinsci/ec2-plugin/#securing-the-connection-to-windows-amis).

Affected Packages

Maven org.jenkins-ci.plugins:ec2
Affected versions: 0 (fixed in 1.50.2)

Related CVEs

Key Information

GHSA ID
GHSA-c89c-pvm7-33wj
Published
May 24, 2022 5:17 PM
Last Modified
December 16, 2022 10:48 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:ec2
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.