Vulnerability GHSA-cm7j-p8hc-97vj
Medium Risk
MEDIUM RISK
CVSS Score: 4.8
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 years ago
July 28, 2022 at 12:00 AM UTC
Jenkins Git client plugin 3.11.0 does not perform SSH host key verification
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.11.0
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.11.0
Summary
Jenkins Git client plugin 3.11.0 does not perform SSH host key verification
Details
Jenkins Git client plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks. Git client Plugin 3.11.1 provides strategies for performing host key verification for administrators to select the one that meets their security needs. For more information see the plugin documentation.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 months ago
Jenkins Git client Plugin has an OS command injection vulnerability on agents
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.5.0 - 6.6.0 GHSA-wp5x-hrrw-6r4g
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.5.0 - 6.6.0 GHSA-wp5x-hrrw-6r4g
Medium Risk
9 months ago
Jenkins Git client Plugin has an OS command injection vulnerability on agents in Git client Plugin
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.4.0 GHSA-v8hg-m323-jvjq
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.4.0 GHSA-v8hg-m323-jvjq
Medium Risk
1 year ago
Jenkins Git client Plugin file system information disclosure vulnerability
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 GHSA-g2pq-9jr7-w6gv
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 GHSA-g2pq-9jr7-w6gv
High Risk
4 years ago
Improper Neutralization of Special Elements used in an OS Command in Jenkins Git Client Plugin
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 GHSA-hw6x-2qwv-rxr7
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 GHSA-hw6x-2qwv-rxr7
Low Risk
4 years ago
Insecure temporary file usage in Jenkins Git Client Plugin
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 GHSA-fcxw-hhxq-48wx
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 GHSA-fcxw-hhxq-48wx
Impacted packages
Timeline
Published
4 years ago
July 28, 2022 at 12:00 AM UTC
Last Modified
2 years ago
February 16, 2024 at 08:16 AM UTC