Unauthenticated Information Exposure in Jenkins Git Plugin
CVE-2022-36884
5.3MEDIUM
Summary
The webhook endpoint in Jenkins Git Plugin versions up to 4.11.3 is susceptible to unauthenticated attacks, allowing malicious users to gain knowledge about jobs that utilize a specified Git repository. This vulnerability enables attackers to enumerate existing jobs without authentication, thereby risking confidential project insights and potentially leading to further exploitation.
Affected Version(s)
Jenkins Git Plugin <= 4.11.3
Jenkins Git Plugin 4.9.3
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved