Vulnerability GHSA-cm7j-p8hc-97vj

Medium Risk
MEDIUM RISK
CVSS Score: 4.8
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 years ago
July 28, 2022 at 12:00 AM UTC
Jenkins Git client plugin 3.11.0 does not perform SSH host key verification
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.11.0
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.11.0

Summary

Jenkins Git client plugin 3.11.0 does not perform SSH host key verification

Details

Jenkins Git client plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks. Git client Plugin 3.11.1 provides strategies for performing host key verification for administrators to select the one that meets their security needs. For more information see the plugin documentation.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
3 months ago
Jenkins Git client Plugin has an OS command injection vulnerability on agents
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.5.0 - 6.6.0 GHSA-wp5x-hrrw-6r4g
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.5.0 - 6.6.0 GHSA-wp5x-hrrw-6r4g
Medium Risk
9 months ago
Jenkins Git client Plugin has an OS command injection vulnerability on agents in Git client Plugin
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.4.0 GHSA-v8hg-m323-jvjq
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.4.0 GHSA-v8hg-m323-jvjq
Medium Risk
1 year ago
Jenkins Git client Plugin file system information disclosure vulnerability
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 GHSA-g2pq-9jr7-w6gv
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 GHSA-g2pq-9jr7-w6gv
High Risk
4 years ago
Improper Neutralization of Special Elements used in an OS Command in Jenkins Git Client Plugin
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 GHSA-hw6x-2qwv-rxr7
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 GHSA-hw6x-2qwv-rxr7
Low Risk
4 years ago
Insecure temporary file usage in Jenkins Git Client Plugin
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 GHSA-fcxw-hhxq-48wx
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 GHSA-fcxw-hhxq-48wx
View all vulnerabilities for these packages

Timeline

Published
4 years ago
July 28, 2022 at 12:00 AM UTC
Last Modified
2 years ago
February 16, 2024 at 08:16 AM UTC