PT-2022-5835 · Jenkins · Jenkins Git Client Plugin+1

Alex Kurtser

+1

·

Published

2022-07-27

·

Updated

2023-11-22

·

CVE-2022-36881

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Git client Plugin versions 3.11.0 and earlier
Description The issue is related to the lack of SSH host key verification when connecting to Git repositories via SSH, which enables man-in-the-middle attacks. This is due to shortcomings in the authentication procedure. The exploitation of this issue can allow a remote attacker to implement a man-in-the-middle attack.
Recommendations For Jenkins Git client Plugin versions 3.11.0 and earlier, update to version 3.11.1 or later, which provides strategies for performing host key verification, allowing administrators to select the one that meets their security needs.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-07248
CVE-2022-36881
GHSA-CM7J-P8HC-97VJ
RHSA-2022:7865
RHSA-2023:0017

Affected Products

Jenkins
Jenkins Git Client Plugin