VYPR
Moderate severityNVD Advisory· Published Jul 27, 2018· Updated Aug 5, 2024

CVE-2017-2648

CVE-2017-2648

Description

It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:ssh-slavesMaven
< 1.151.15

Affected products

2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.