GHSA-x654-4wjh-74q6
GitHub Security Advisory
Jenkins SSH Build Agents Plugin did not verify host keys
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.
Affected Packages
Maven
org.jenkins-ci.plugins:ssh-slaves
Affected versions:
0
(fixed in 1.15)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 5, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.