cbcvebase.
CVE-2022-30947
published 2022-05-17

CVE-2022-30947: Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file…

PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.22%
65.1th percentile
Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

Affected

22 ranges
VendorProductVersion rangeFixed in
jenkinsapplication_detector_plugin
jenkinsautocomplete_parameter_plugin
jenkinsblue_ocean_plugin
jenkinsgit< 4.11.24.11.2
jenkinsgit_plugin
jenkinsgitlab_plugin
jenkinsglobal_variable_string_parameter_plugin
jenkinsgroovy_plugin
jenkinshttp_requests_in_script_security_plugin
jenkinsjdk_parameter_plugin
jenkinsjenkins_core
jenkinsmercurial_plugin
jenkinsmultiselect_parameter_plugin
jenkinsrandom_string_parameter_plugin
jenkinsrepo_plugin
jenkinsrundeck_plugin
jenkinsscript_security_plugin
jenkinsselection_tasks_plugin
jenkinsssh_plugin
jenkinsstorable_configs_plugin
jenkinswhile_credentials_plugin
jenkins_projectjenkins_git_pluginunspecified – 4.11.1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.