Description
The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6223 | The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository. |
Github GHSA |
GHSA-449w-c77c-vmf6 | Lack of authentication mechanism in Jenkins Git Plugin webhook |
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T10:14:29.343Z
Reserved: 2022-07-27T00:00:00.000Z
Link: CVE-2022-36884
No data.
Status : Modified
Published: 2022-07-27T15:15:08.933
Modified: 2024-11-21T07:13:59.117
Link: CVE-2022-36884
OpenCVE Enrichment
No data.
EUVD
Github GHSA