Vulnerabilities
Vulnerable Software
Jenkins:  >> Git  >> 4.11.2  Security Vulnerabilities
Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePassword`) credentials binding.
CVSS Score
6.5
EPSS Score
0.007
Published
2022-08-23
A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.
CVSS Score
8.8
EPSS Score
0.006
Published
2022-07-27
A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.
CVSS Score
7.5
EPSS Score
0.574
Published
2022-07-27
The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.
CVSS Score
5.3
EPSS Score
0.005
Published
2022-07-27


Contact Us

Shodan ® - All rights reserved