Showing 7 vulnerabilities on this page for Jenkins Git Plugin

Signals CISA KEV Ransomware Nuclei
Jenkins project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Improper masking of credentials Jenkins in Git Plugin

Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePassword`) credentials binding.

CWE-522Aug 23, 2022
CVSS6.5v3.1EPSS0.809%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Lack of authentication mechanism in Jenkins Git Plugin webhook

The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.

CWE-200CWE-306Jul 27, 2022
CVSS5.3v3.1EPSS0.991%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Lack of authentication mechanism in Jenkins Git Plugin webhook

A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.

CWE-862Jul 27, 20221 related artifact
CVSS7.5v3.1EPSS6.45%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Lack of authentication mechanism in Jenkins Git Plugin webhook

A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.

CWE-352Jul 27, 2022
CVSS8.8v3.1EPSS0.673%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Path traversal in Jenkins Git Mercurial and Repo Plugins

Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

CWE-22May 17, 2022
CVSS7.5v3.1EPSS1.25%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Stored XSS vulnerability in Jenkins Git Plugin

Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.

CWE-116CWE-79Oct 6, 2021
CVSS6.1v3.1EPSS1.24%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Neutralization of Input During Web Page Generation in Jenkins Git Plugin

Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.

CWE-79Mar 9, 2020
CVSS5.4v3.1EPSS0.853%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX