Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alex Kurtser

Researcher fromSatori Cyber Ltd.
#31487of 53,635
8.1Total CVSS
Vulnerabilities · 1
PT-2022-5835
8.1
2022-07-27
Jenkins · Jenkins Git Client Plugin · CVE-2022-36881
**Name of the Vulnerable Software and Affected Versions** Jenkins Git client Plugin versions 3.11.0 and earlier **Description** The issue is related to the lack of SSH host key verification when connecting to Git repositories via SSH, which enables man-in-the-middle attacks. This is due to shortcomings in the authentication procedure. The exploitation of this issue can allow a remote attacker to implement a man-in-the-middle attack. **Recommendations** For Jenkins Git client Plugin versions 3.11.0 and earlier, update to version 3.11.1 or later, which provides strategies for performing host key verification, allowing administrators to select the one that meets their security needs.