This repository has been archived by the owner on Oct 2, 2023. It is now read-only.
CVE-2022-36884 (Medium) detected in git-4.2.1.jar #168
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2022-36884 - Medium Severity Vulnerability
Vulnerable Library - git-4.2.1.jar
Integrates Jenkins with Git SCM
Library home page: https://github.com/jenkinsci/git-plugin/tree/git-4.2.1/README.adoc
Path to dependency file: /pom.xml
Path to vulnerable library: /-ci/plugins/git/4.2.1/git-4.2.1.jar
Dependency Hierarchy:
Found in HEAD commit: 97ed2b7fe477b78f0b26191e5950825314db7b2c
Found in base branch: master
Vulnerability Details
The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.
Publish Date: 2022-07-27
URL: CVE-2022-36884
CVSS 3 Score Details (5.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-284
Release Date: 2022-07-27
Fix Resolution: org.jenkins-ci.plugins:git:4.11.4
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: