Unauthenticated Information Exposure in Jenkins Git Plugin
CVE-2022-36884
5.3MEDIUM
Key Information:
- Vendor
Jenkins
- Status
- Vendor
- CVE Published:
- 27 July 2022
What is CVE-2022-36884?
The webhook endpoint in Jenkins Git Plugin versions up to 4.11.3 is susceptible to unauthenticated attacks, allowing malicious users to gain knowledge about jobs that utilize a specified Git repository. This vulnerability enables attackers to enumerate existing jobs without authentication, thereby risking confidential project insights and potentially leading to further exploitation.
Affected Version(s)
Jenkins Git Plugin <= 4.11.3
Jenkins Git Plugin 4.9.3