plugin: Lack of authentication mechanism in Git Plugin webhook
Published Jul 27, 2022
7.5
HIGHCVSS 3.1
EPSS 6.88%
Description
A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.
Affected products
-
Affected
- ≥ unspecified, ≤ 4.11.3
Unaffected
- 4.9.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Jenkins project | Jenkins Git Plugin | unknown | Affected
Unaffected
|
No data.
Red Hat OpenShift Container Platform 4.10
jenkins-2-plugins-0:4.10.1675144701-1.el8
Fixed · RHSA-2023:0560
Red Hat OpenShift Container Platform 4.8
jenkins-2-plugins-0:4.8.1672842762-1.el8
Fixed · RHSA-2023:0017
Red Hat OpenShift Container Platform 4.9
jenkins-2-plugins-0:4.9.1675668922-1.el8
Fixed · RHSA-2023:0777
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4.10 | jenkins-2-plugins-0:4.10.1675144701-1.el8 | Fixed | RHSA-2023:0560 |
| Red Hat OpenShift Container Platform 4.8 | jenkins-2-plugins-0:4.8.1672842762-1.el8 | Fixed | RHSA-2023:0017 |
| Red Hat OpenShift Container Platform 4.9 | jenkins-2-plugins-0:4.9.1675668922-1.el8 | Fixed | RHSA-2023:0777 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- http://www.openwall.com/lists/oss-security/2022/07/27/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-36883 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2119656 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6419 Advisory
- https://github.com/advisories/GHSA-v878-67xw-grw2 Advisory
- https://github.com/jenkinsci/git-plugin/commit/b46165c74a0bf15e08763de2e506005624d5d238
- https://nvd.nist.gov/vuln/detail/CVE-2022-36883
- https://www.cve.org/CVERecord?id=CVE-2022-36883
- https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-284 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2022/07/27/1 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2022-36883 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2119656 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6419 | Advisory | |
| https://github.com/advisories/GHSA-v878-67xw-grw2 | Advisory | |
| https://github.com/jenkinsci/git-plugin/commit/b46165c74a0bf15e08763de2e506005624d5d238 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-36883 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-36883 | ||
| https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-284 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub