Jenkins Git 4.11.3 for Jenkins

CPE Details

Jenkins Git 4.11.3 for Jenkins
4.11.3
2022-08-01
15h44 +00:00
2022-08-02
12h23 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:jenkins:git:4.11.3:*:*:*:*:jenkins:*:*

Informations

Vendor

jenkins

Product

git

Version

4.11.3

Target Software

jenkins

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-38663 2022-08-23 14h45 +00:00 Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePassword`) credentials binding.
6.5
Medium
CVE-2022-36884 2022-07-27 12h21 +00:00 The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.
5.3
Medium
CVE-2022-36883 2022-07-27 12h21 +00:00 A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.
7.5
High
CVE-2022-36882 2022-07-27 12h20 +00:00 A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.
8.8
High