#VU22922 Man-in-the-Middle (MitM) attack in Google Compute Engine - CVE-2019-16546
Published: November 22, 2019
Google Compute Engine
Jenkins
Description
The vulnerability allows a remote attacker to perform a man-in-the-middle (MitM) attack.
The vulnerability exists due to the affected plugin does not use SSH host key verification when connecting to VMs launched by the plugin. A remote attacker can perform a man-in-the-middle attack to intercept these connections to attacker-specified build agents without warning.