Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade cri-oUpgrade openshift-ansibleUpgrade openshift-kuryrUpgrade openshiftUpgrade machine-config-daemonUpgrade slirp4netnsUpgrade jenkinsUpgrade atomic-enterprise-service-catalogUpgrade openshift-clientsUpgrade jenkins-2-pluginsUpgrade runcUpgrade atomic-openshift-service-idlerUpgrade skopeoUpgrade podmanUpgrade toolboxUpgrade cri-toolsUpgrade dracut | Apr 3, 2020 | Sep 12, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub