CVE-2018-1000149

MEDIUM

Jenkins Ansible Plugin <0.8 - Man in the Middle

Title source: llm
STIX 2.1

Description

A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, AnsibleAdHocCommandInvocationTest.java, AnsibleContext.java, AnsibleJobDslExtension.java, AnsiblePlaybookBuilder.java, AnsiblePlaybookStep.java that disables host key verification by default.

References (1)

Core 1
Core References

Scores

CVSS v3 5.6
EPSS 0.0007
EPSS Percentile 22.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

Status published
Products (2)
jenkins/ansible < 0.8
org.jenkins-ci.plugins/ansible 0 - 1.0Maven
Published Apr 05, 2018
Tracked Since Feb 18, 2026