CVE Database
/

CVE-2019-16546

Back to search

CVE-2019-16546

Published: Nov 21, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.

VendorProductVersions

Jenkins project

Jenkins Google Compute Engine Plugin

affected
4.1.1 and earlier

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now