cbcvebase.
CVE-2022-36881
published 2022-07-27

CVE-2022-36881: Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle…

PriorityP339high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.97%
60.4th percentile
Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsandroid_signing_plugin——
jenkinsbmc_ami_devx_code_debug_code_coverage_plugin——
jenkinsbmc_ami_devx_code_pipeline_operations_plugin——
jenkinsbuckminster_plugin——
jenkinsclif_performance_testing_plugin——
jenkinscode_pipeline_plugin——
jenkinscompuware_topaz_utilities_plugin——
jenkinscoverity_plugin——
jenkinsdeployer_framework_plugin——
jenkinsdynamic_extended_choice_parameter_plugin——
jenkinsexternal_monitor_job_type_plugin——
jenkinsfiles_found_trigger_plugin——
jenkinsfor_more_information_see_the_plugin——
jenkinsgit_client<= 3.11.0—
jenkinsgit_client_plugin——
jenkinsgit_plugin——
jenkinsgithub_plugin——
jenkinsgoogle_cloud_backup_plugin——
jenkinshashicorp_vault_plugin——
jenkinshttp_request_plugin——
jenkinsjenkins_ci_server_plugin——
jenkinsjob_configuration_history_plugin——
jenkinslack_of_authentication_mechanism_in_git_plugin——
jenkinslucene-search_plugin——
jenkinsmaven_metadata_plugin——

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.