jenkins-git-client-plugin: OS command injection via 'git ls-remote'
Published Sep 12, 2019
8.8
HIGHCVSS 3.1
EPSS 26.23%
Description
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
Affected products
-
Affected
- 2.8.4 and earlier, 3.0.0-rc
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Jenkins project | Jenkins Git Client Plugin | unknown | Affected
|
- ≤ 2.8.4
- 3.0.0
No data.
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins-0:3.11.1591354111-1.el7
Fixed · RHSA-2020:2478
Red Hat OpenShift Container Platform 4.1
atomic-enterprise-service-catalog-1:4.1.37-202003020601.git.0.5784dc4.el7
Fixed · RHBA-2020:0690
Red Hat OpenShift Container Platform 4.1
cri-o-0:1.13.12-6.dev.rhaos4.1.git8abaaeb.el7
Fixed · RHBA-2020:0690
Red Hat OpenShift Container Platform 4.1
jenkins-0:2.204.2.1583849753-1.el7
Fixed · RHBA-2020:0690
Red Hat OpenShift Container Platform 4.1
jenkins-2-plugins-0:4.1.1583850385-1.el7
Fixed · RHBA-2020:0690
Red Hat OpenShift Container Platform 4.1
openshift-0:4.1.37-202002280447.git.0.543873e.el7
Fixed · RHBA-2020:0690
Red Hat OpenShift Container Platform 4.1
openshift-ansible-0:4.1.37-202002280447.git.1.bb180eb.el7
Fixed · RHBA-2020:0690
Red Hat OpenShift Container Platform 4.1
podman-0:1.0.2-3.dev.git96ccc2e.el8_0
Fixed · RHBA-2020:0690
Red Hat OpenShift Container Platform 4.1
runc-0:1.0.0-63.rc8.rhaos4.1.git3cbe540.el8_0
Fixed · RHBA-2020:0690
Red Hat OpenShift Container Platform 4.1
skopeo-1:0.1.32-6.git1715c90.el8_0
Fixed · RHBA-2020:0690
Red Hat OpenShift Container Platform 4.2
atomic-enterprise-service-catalog-1:4.2.20-202002170402.git.1.159e2f5.el7
Fixed · RHBA-2020:0522
Red Hat OpenShift Container Platform 4.2
atomic-openshift-service-idler-0:4.2.20-202002170402.git.1.43218bc.el7
Fixed · RHBA-2020:0522
Red Hat OpenShift Container Platform 4.2
cri-o-0:1.14.12-10.dev.rhaos4.2.git313d784.el8
Fixed · RHBA-2020:0522
Red Hat OpenShift Container Platform 4.2
jenkins-0:2.204.1.1581951349-1.el7
Fixed · RHBA-2020:0522
Red Hat OpenShift Container Platform 4.2
jenkins-2-plugins-0:4.2.1581952573-1.el7
Fixed · RHBA-2020:0522
Red Hat OpenShift Container Platform 4.2
machine-config-daemon-0:4.2.20-202002170402.git.1.a83336a.el8
Fixed · RHBA-2020:0522
Red Hat OpenShift Container Platform 4.2
openshift-0:4.2.20-202002140432.git.0.47933cb.el7
Fixed · RHBA-2020:0522
Red Hat OpenShift Container Platform 4.2
openshift-ansible-0:4.2.20-202002140432.git.187.2308b53.el7
Fixed · RHBA-2020:0522
Red Hat OpenShift Container Platform 4.2
openshift-clients-0:4.2.20-202002140432.git.1.5dc67c9.el7
Fixed · RHBA-2020:0522
Red Hat OpenShift Container Platform 4.2
openshift-kuryr-0:4.2.20-202002140432.git.1.d9a72a5.el7
Fixed · RHBA-2020:0522
Red Hat OpenShift Container Platform 4.3
atomic-enterprise-service-catalog-1:4.3.3-202002170501.git.1.f30799e.el7
Fixed · RHBA-2020:0527
Red Hat OpenShift Container Platform 4.3
atomic-openshift-service-idler-0:4.3.3-202002170501.git.1.4feff9c.el7
Fixed · RHBA-2020:0527
Red Hat OpenShift Container Platform 4.3
cri-o-0:1.16.3-20.dev.rhaos4.3.git11c04e3.el7
Fixed · RHBA-2020:0527
Red Hat OpenShift Container Platform 4.3
cri-tools-0:1.17.0-1.el8
Fixed · RHBA-2020:0527
Red Hat OpenShift Container Platform 4.3
dracut-0:049-64.git20200123.el8
Fixed · RHBA-2020:0527
Red Hat OpenShift Container Platform 4.3
jenkins-0:2.204.1.1581950993-1.el7
Fixed · RHBA-2020:0527
Red Hat OpenShift Container Platform 4.3
jenkins-2-plugins-0:4.3.1581956184-1.el7
Fixed · RHBA-2020:0527
Red Hat OpenShift Container Platform 4.3
machine-config-daemon-0:4.3.3-202002170501.git.1.6b1b155.el8
Fixed · RHBA-2020:0527
Red Hat OpenShift Container Platform 4.3
openshift-0:4.3.3-202002140552.git.0.e38059c.el7
Fixed · RHBA-2020:0527
Red Hat OpenShift Container Platform 4.3
openshift-ansible-0:4.3.3-202002142331.git.173.bb0b5a1.el7
Fixed · RHBA-2020:0527
Red Hat OpenShift Container Platform 4.3
openshift-clients-0:4.3.3-202002140552.git.1.ff73b47.el7
Fixed · RHBA-2020:0527
Red Hat OpenShift Container Platform 4.3
openshift-kuryr-0:4.3.3-202002170501.git.1.3b8b4cc.el8
Fixed · RHBA-2020:0527
Red Hat OpenShift Container Platform 4.3
slirp4netns-0:0.4.2-4.git21fdece.el8
Fixed · RHBA-2020:0527
Red Hat OpenShift Container Platform 4.3
toolbox-0:0.0.6-1.rhaos4.3.el8
Fixed · RHBA-2020:0527
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins-0:3.11.1591354111-1.el7 | Fixed | RHSA-2020:2478 |
| Red Hat OpenShift Container Platform 4.1 | atomic-enterprise-service-catalog-1:4.1.37-202003020601.git.0.5784dc4.el7 | Fixed | RHBA-2020:0690 |
| Red Hat OpenShift Container Platform 4.1 | cri-o-0:1.13.12-6.dev.rhaos4.1.git8abaaeb.el7 | Fixed | RHBA-2020:0690 |
| Red Hat OpenShift Container Platform 4.1 | jenkins-0:2.204.2.1583849753-1.el7 | Fixed | RHBA-2020:0690 |
| Red Hat OpenShift Container Platform 4.1 | jenkins-2-plugins-0:4.1.1583850385-1.el7 | Fixed | RHBA-2020:0690 |
| Red Hat OpenShift Container Platform 4.1 | openshift-0:4.1.37-202002280447.git.0.543873e.el7 | Fixed | RHBA-2020:0690 |
| Red Hat OpenShift Container Platform 4.1 | openshift-ansible-0:4.1.37-202002280447.git.1.bb180eb.el7 | Fixed | RHBA-2020:0690 |
| Red Hat OpenShift Container Platform 4.1 | podman-0:1.0.2-3.dev.git96ccc2e.el8_0 | Fixed | RHBA-2020:0690 |
| Red Hat OpenShift Container Platform 4.1 | runc-0:1.0.0-63.rc8.rhaos4.1.git3cbe540.el8_0 | Fixed | RHBA-2020:0690 |
| Red Hat OpenShift Container Platform 4.1 | skopeo-1:0.1.32-6.git1715c90.el8_0 | Fixed | RHBA-2020:0690 |
| Red Hat OpenShift Container Platform 4.2 | atomic-enterprise-service-catalog-1:4.2.20-202002170402.git.1.159e2f5.el7 | Fixed | RHBA-2020:0522 |
| Red Hat OpenShift Container Platform 4.2 | atomic-openshift-service-idler-0:4.2.20-202002170402.git.1.43218bc.el7 | Fixed | RHBA-2020:0522 |
| Red Hat OpenShift Container Platform 4.2 | cri-o-0:1.14.12-10.dev.rhaos4.2.git313d784.el8 | Fixed | RHBA-2020:0522 |
| Red Hat OpenShift Container Platform 4.2 | jenkins-0:2.204.1.1581951349-1.el7 | Fixed | RHBA-2020:0522 |
| Red Hat OpenShift Container Platform 4.2 | jenkins-2-plugins-0:4.2.1581952573-1.el7 | Fixed | RHBA-2020:0522 |
| Red Hat OpenShift Container Platform 4.2 | machine-config-daemon-0:4.2.20-202002170402.git.1.a83336a.el8 | Fixed | RHBA-2020:0522 |
| Red Hat OpenShift Container Platform 4.2 | openshift-0:4.2.20-202002140432.git.0.47933cb.el7 | Fixed | RHBA-2020:0522 |
| Red Hat OpenShift Container Platform 4.2 | openshift-ansible-0:4.2.20-202002140432.git.187.2308b53.el7 | Fixed | RHBA-2020:0522 |
| Red Hat OpenShift Container Platform 4.2 | openshift-clients-0:4.2.20-202002140432.git.1.5dc67c9.el7 | Fixed | RHBA-2020:0522 |
| Red Hat OpenShift Container Platform 4.2 | openshift-kuryr-0:4.2.20-202002140432.git.1.d9a72a5.el7 | Fixed | RHBA-2020:0522 |
| Red Hat OpenShift Container Platform 4.3 | atomic-enterprise-service-catalog-1:4.3.3-202002170501.git.1.f30799e.el7 | Fixed | RHBA-2020:0527 |
| Red Hat OpenShift Container Platform 4.3 | atomic-openshift-service-idler-0:4.3.3-202002170501.git.1.4feff9c.el7 | Fixed | RHBA-2020:0527 |
| Red Hat OpenShift Container Platform 4.3 | cri-o-0:1.16.3-20.dev.rhaos4.3.git11c04e3.el7 | Fixed | RHBA-2020:0527 |
| Red Hat OpenShift Container Platform 4.3 | cri-tools-0:1.17.0-1.el8 | Fixed | RHBA-2020:0527 |
| Red Hat OpenShift Container Platform 4.3 | dracut-0:049-64.git20200123.el8 | Fixed | RHBA-2020:0527 |
| Red Hat OpenShift Container Platform 4.3 | jenkins-0:2.204.1.1581950993-1.el7 | Fixed | RHBA-2020:0527 |
| Red Hat OpenShift Container Platform 4.3 | jenkins-2-plugins-0:4.3.1581956184-1.el7 | Fixed | RHBA-2020:0527 |
| Red Hat OpenShift Container Platform 4.3 | machine-config-daemon-0:4.3.3-202002170501.git.1.6b1b155.el8 | Fixed | RHBA-2020:0527 |
| Red Hat OpenShift Container Platform 4.3 | openshift-0:4.3.3-202002140552.git.0.e38059c.el7 | Fixed | RHBA-2020:0527 |
| Red Hat OpenShift Container Platform 4.3 | openshift-ansible-0:4.3.3-202002142331.git.173.bb0b5a1.el7 | Fixed | RHBA-2020:0527 |
| Red Hat OpenShift Container Platform 4.3 | openshift-clients-0:4.3.3-202002140552.git.1.ff73b47.el7 | Fixed | RHBA-2020:0527 |
| Red Hat OpenShift Container Platform 4.3 | openshift-kuryr-0:4.3.3-202002170501.git.1.3b8b4cc.el8 | Fixed | RHBA-2020:0527 |
| Red Hat OpenShift Container Platform 4.3 | slirp4netns-0:0.4.2-4.git21fdece.el8 | Fixed | RHBA-2020:0527 |
| Red Hat OpenShift Container Platform 4.3 | toolbox-0:0.0.6-1.rhaos4.3.el8 | Fixed | RHBA-2020:0527 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- http://www.openwall.com/lists/oss-security/2019/09/12/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-10392 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1819704 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4225 Advisory
- https://github.com/advisories/GHSA-hw6x-2qwv-rxr7 Advisory
- https://github.com/jenkinsci/git-client-plugin/commit/899123fa2eb9dd2c37137aae630c47c6be6b4b02
- https://jenkins.io/security/advisory/2019-09-12/#SECURITY-1534 x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10392
- https://www.cve.org/CVERecord?id=CVE-2019-10392
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2019/09/12/2 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-10392 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1819704 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4225 | Advisory | |
| https://github.com/advisories/GHSA-hw6x-2qwv-rxr7 | Advisory | |
| https://github.com/jenkinsci/git-client-plugin/commit/899123fa2eb9dd2c37137aae630c47c6be6b4b02 | ||
| https://jenkins.io/security/advisory/2019-09-12/#SECURITY-1534 | x_refsource_MISCVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-10392 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-10392 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub