A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, AnsibleAdHocCommandInvocationTest.java, AnsibleContext.java, AnsibleJobDslExtension.java, AnsiblePlaybookBuilder.java, AnsiblePlaybookStep.java that disables host key verification by default.
2018-04-05T13:29:00.637
2024-11-21T03:39:47.683
Modified
CVSSv3.0: 5.6 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4