Back

HIGH

plugin: Lack of authentication mechanism in Git Plugin webhook

Published Jul 27, 2022

Description

A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner jenkins
Published Jul 27, 2022
Updated Aug 3, 2024
Reserved Jul 27, 2022

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jul 27, 2022
Bugzilla 2119656

ENISA EUVD

Assigner jenkins
Published Jul 27, 2022
Updated Aug 3, 2024