CVE-2019-16546: Jenkins Google Compute Engine

Medium severity, CVSS 5.9. EPSS: 0.9% chance of exploitation in the next 30 days.

Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.

Affected products

  • Jenkins Google Compute Engine: before 4.2.0 (fixed in 4.2.0)

Published 2019-11-21. Last modified 2026-06-17.