Vulnerability GHSA-hw6x-2qwv-rxr7

High Risk
HIGH RISK
CVSS Score: 8.8
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
4 years ago
May 24, 2022 at 04:55 PM UTC
Improper Neutralization of Special Elements used in an OS Command in Jenkins Git Client Plugin
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4

Summary

Improper Neutralization of Special Elements used in an OS Command in Jenkins Git Client Plugin

Details

Jenkins Git Client Plugin 2.8.4 and earlier did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
3 months ago
Jenkins Git client Plugin has an OS command injection vulnerability on agents
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.5.0 - 6.6.0 GHSA-wp5x-hrrw-6r4g
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.5.0 - 6.6.0 GHSA-wp5x-hrrw-6r4g
Medium Risk
9 months ago
Jenkins Git client Plugin has an OS command injection vulnerability on agents in Git client Plugin
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.4.0 GHSA-v8hg-m323-jvjq
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.4.0 GHSA-v8hg-m323-jvjq
Medium Risk
1 year ago
Jenkins Git client Plugin file system information disclosure vulnerability
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 GHSA-g2pq-9jr7-w6gv
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 GHSA-g2pq-9jr7-w6gv
Medium Risk
4 years ago
Jenkins Git client plugin 3.11.0 does not perform SSH host key verification
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.11.0 GHSA-cm7j-p8hc-97vj
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.11.0 GHSA-cm7j-p8hc-97vj
Low Risk
4 years ago
Insecure temporary file usage in Jenkins Git Client Plugin
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 GHSA-fcxw-hhxq-48wx
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 GHSA-fcxw-hhxq-48wx
View all vulnerabilities for these packages

Timeline

Published
4 years ago
May 24, 2022 at 04:55 PM UTC
Last Modified
2 years ago
February 16, 2024 at 08:18 AM UTC