vulnerability
Red Hat OpenShift: CVE-2022-36884: plugin: Lack of authentication mechanism in Git Plugin webhook
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:N/AC:L/Au:N/C:P/I:N/A:N) | Jul 27, 2022 | Jan 13, 2023 | Apr 14, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Jul 27, 2022
Added
Jan 13, 2023
Modified
Apr 14, 2025
Description
The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.
Solution
linuxrpm-upgrade-jenkins-2-plugins

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.