{"id":"CVE-2017-2648","details":"It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.","aliases":["GHSA-x654-4wjh-74q6"],"modified":"2026-08-27T08:18:47.488548Z","published":"2018-07-27T20:29:00.390Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/96985"},{"type":"ADVISORY","url":"https://jenkins.io/security/advisory/2017-03-20/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2648"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jenkinsci/ssh-agents-plugin","events":[{"introduced":"0"},{"fixed":"8ba96d91dcf6f471a6faff5f9c4f37469e3d91c1"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.15"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:jenkins:ssh_slaves:*:*:*:*:*:jenkins:*:*"}}],"versions":["ssh-slaves-1.14","ssh-slaves-1.13","ssh-slaves-1.12","ssh-slaves-1.11","ssh-slaves-1.10","ssh-slaves-1.9","ssh-slaves-1.8","ssh-slaves-1.7.1","ssh-slaves-1.7","ssh-slaves-1.6","ssh-slaves-1.5","ssh-slaves-1.4","ssh-slaves-1.3","ssh-slaves-1.2","ssh-slaves-1.1","ssh-slaves-1.0","ssh-slaves-0.27","ssh-slaves-0.26","ssh-slaves-0.25","ssh-slaves-0.24","ssh-slaves-0.23","ssh-slaves-0.22","ssh-slaves-0.21","ssh-slaves-0.20","ssh-slaves-0.19","ssh-slaves-0.18","ssh-slaves-0.17","ssh-slaves-0.16","ssh-slaves-0.15"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-2648.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}