Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Alex Kurtser

Researcher fromSatori Cyber Ltd.
#32446of 55,077
8.1Total CVSS
Vulnerabilities · 1
PT-2022-5835
8.1
2022-07-27
Jenkins · Jenkins Git Client Plugin · CVE-2022-36881
**Name of the Vulnerable Software and Affected Versions** Jenkins Git client Plugin versions 3.11.0 and earlier **Description** The issue is related to the lack of SSH host key verification when connecting to Git repositories via SSH, which enables man-in-the-middle attacks. This is due to shortcomings in the authentication procedure. The exploitation of this issue can allow a remote attacker to implement a man-in-the-middle attack. **Recommendations** For Jenkins Git client Plugin versions 3.11.0 and earlier, update to version 3.11.1 or later, which provides strategies for performing host key verification, allowing administrators to select the one that meets their security needs.