Unauthenticated Information Exposure in Jenkins Git Plugin
CVE-2022-36884

5.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
27 July 2022

Summary

The webhook endpoint in Jenkins Git Plugin versions up to 4.11.3 is susceptible to unauthenticated attacks, allowing malicious users to gain knowledge about jobs that utilize a specified Git repository. This vulnerability enables attackers to enumerate existing jobs without authentication, thereby risking confidential project insights and potentially leading to further exploitation.

Affected Version(s)

Jenkins Git Plugin <= 4.11.3

Jenkins Git Plugin 4.9.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.