Jenkins · Jenkins Git Client Plugin · CVE-2022-36881
**Name of the Vulnerable Software and Affected Versions**
Jenkins Git client Plugin versions 3.11.0 and earlier
**Description**
The issue is related to the lack of SSH host key verification when connecting to Git repositories via SSH, which enables man-in-the-middle attacks. This is due to shortcomings in the authentication procedure. The exploitation of this issue can allow a remote attacker to implement a man-in-the-middle attack.
**Recommendations**
For Jenkins Git client Plugin versions 3.11.0 and earlier, update to version 3.11.1 or later, which provides strategies for performing host key verification, allowing administrators to select the one that meets their security needs.