Description
Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9Attack Vector: Network
Complexity: High
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages3 packages
🔴Vulnerability Details
3OSVJenkins Git client plugin 3.11.0 does not perform SSH host key verification↗2022-07-28 ▶ GHSAJenkins Git client plugin 3.11.0 does not perform SSH host key verification↗2022-07-28 ▶ CVEListCVE-2022-36881: Jenkins Git client Plugin 3↗2022-07-27 ▶ 📋Vendor Advisories
2Red Hatjenkins-plugin: Man-in-the-Middle (MitM) in org.jenkins-ci.plugins:git-client↗2022-08-03 ▶ JenkinsJenkins Security Advisory 2022-07-27↗2022-07-27 ▶