GHSA-rv9g-67f7-grq7
GitHub Security Advisory
Missing SSH host key validation in Mac Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Mac Plugin 1.1.0 and earlier does not use SSH host key validation when connecting to Mac Cloud host launched by the plugin. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections to build agents.
Mac Plugin 1.2.0 validates SSH host keys when connecting to agents.
Affected Packages
Maven
fr.edf.jenkins.plugins:mac
Affected versions:
0
(fixed in 1.2.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 24, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.