cbcvebase.
CVE-2020-2146
published 2020-03-09

CVE-2020-2146: Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.

PriorityP434high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.57%
43.3th percentile
Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsaudit_trail_plugin
jenkinsbacklog_plugin
jenkinschaos_monkey_plugin
jenkinscobertura_plugin
jenkinscredentials_plugin
jenkinscryptomove_plugin
jenkinscvs_plugin
jenkinsdeployhub_plugin
jenkinsdocker_images_of_jenkins_2.269_and_2.263.1_contain_plugin
jenkinsgit_plugin
jenkinsinstallation_manager_tool_did_not_verify_plugin
jenkinsjenkins_is_running_plugin
jenkinsliterate_plugin
jenkinslogstash_plugin
jenkinsmac<= 1.1.0
jenkinsmac_cloud_host_launched_by_the_plugin
jenkinsmac_plugin
jenkinsmanager_tool_2.1.3_and_earlier_does_not_verify_plugin
jenkinsopenshift_deployer_plugin
jenkinsp4_plugin
jenkinsquality_gates_plugin
jenkinsrepository_connector_plugin
jenkinsrundeck_plugin
jenkinssandbox_protection_in_script_security_plugin
jenkinsscript_security_plugin

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.