Description
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hw6x-2qwv-rxr7 | Improper Neutralization of Special Elements used in an OS Command in Jenkins Git Client Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T22:17:20.645Z
Reserved: 2019-03-29T00:00:00.000Z
Link: CVE-2019-10392
No data.
Status : Modified
Published: 2019-09-12T14:15:11.257
Modified: 2024-11-21T04:19:02.203
Link: CVE-2019-10392
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA