vulnerability

Red Hat OpenShift: CVE-2022-36884: plugin: Lack of authentication mechanism in Git Plugin webhook

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Jul 27, 2022
Added
Jan 13, 2023
Modified
Apr 14, 2025

Description

The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.

Solution

linuxrpm-upgrade-jenkins-2-plugins
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.