CVE-2022-30947

HIGH

Jenkins Git Plugin <4.11.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/05/17/8

Scores

CVSS v3 7.5
EPSS 0.0065
EPSS Percentile 70.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (4)
jenkins/git < 4.11.2
org.jenkins-ci.plugins/git 0 - 4.11.2Maven
org.jenkins-ci.plugins/mercurial 0 - 2.16.1Maven
org.jenkins-ci.plugins/repo 0 - 1.15.0Maven
Published May 17, 2022
Tracked Since Feb 18, 2026