CVE-2020-2187
published 2020-05-06CVE-2020-2187: Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling…
PriorityP425medium5.6CVSS 3.1
AVNACHPRNUINSUCLILAL
EPSS
0.41%
33.2th percentile
Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle attacks.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | amazon_ec2 | <= 1.50.1 | — |
| jenkins | amazon_ec2_plugin | — | — |
| jenkins | copy_artifact_plugin | — | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | cvs_plugin | — | — |
| jenkins | for_more_information_see_the_plugin | — | — |
| jenkins | ids_in_amazon_ec2_plugin | — | — |
| jenkins | ids_to_allow_users_configuring_the_plugin | — | — |
| jenkins | scm_filter_jervis_plugin | — | — |
| jenkins | when_updating_the_plugin | — | — |
| jenkins_project | jenkins_amazon_ec2_plugin | unspecified – 1.50.1 | — |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Lack of SSL/TLS certificate and hostname validation in Amazon EC2 Plugin
ghsa·2022-05-24
CVE-2020-2187 [MEDIUM] CWE-295 Lack of SSL/TLS certificate and hostname validation in Amazon EC2 Plugin
Lack of SSL/TLS certificate and hostname validation in Amazon EC2 Plugin
Amazon EC2 Plugin connects to Windows agents via HTTPS.
Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed HTTPS certificates and does not perform hostname validation when connecting to Windows agents. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections to build agents.
Amazon EC2 Plugin 1.50.2 by default no longer accepts self-signed HTTPS certificates and performs hostname validation. A new configuration option allows restoring the previous, unsafe behavior. For more information see [the plugin documentation](https://github.com/jenkinsci/ec2-plugin/#securing-the-connection-to-windows-amis).
OSV
Lack of SSL/TLS certificate and hostname validation in Amazon EC2 Plugin
osv·2022-05-24
CVE-2020-2187 [MEDIUM] Lack of SSL/TLS certificate and hostname validation in Amazon EC2 Plugin
Lack of SSL/TLS certificate and hostname validation in Amazon EC2 Plugin
Amazon EC2 Plugin connects to Windows agents via HTTPS.
Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed HTTPS certificates and does not perform hostname validation when connecting to Windows agents. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections to build agents.
Amazon EC2 Plugin 1.50.2 by default no longer accepts self-signed HTTPS certificates and performs hostname validation. A new configuration option allows restoring the previous, unsafe behavior. For more information see [the plugin documentation](https://github.com/jenkinsci/ec2-plugin/#securing-the-connection-to-windows-amis).
Jenkins
Jenkins Security Advisory 2020-05-06
vendor_jenkins·2020-05-06·CVSS 6.5
CVE-2020-2181 [MEDIUM] Jenkins Security Advisory 2020-05-06
Title: Jenkins Security Advisory 2020-05-06
Jenkins Security Advisory 2020-05-06
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Amazon EC2
Plugin
Copy Artifact
Plugin
Credentials Binding
Plugin
CVS
Plugin
SCM Filter Jervis
Plugin
Descriptions
Secrets are not masked by Credentials Binding Plugin in
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-05-06
Published