CVE-2017-1000092

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-1000092
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-1000092.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-1000092
Aliases
Related
Published
2017-10-05T01:29:03Z
Modified
2024-10-12T02:23:42.075450Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at a username/password credentials ID could trick a developer with job configuration permissions into following a link with a maliciously crafted Jenkins URL which would result in the Jenkins Git client sending the username and password to an attacker-controlled server.

References

Affected packages

Git / github.com/jenkinsci/git-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/git-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected

Affected versions

2.*

2.0-alpha-1
2.0-alpha-2

git-0.*

git-0.9
git-0.9.1
git-0.9.2

git-1.*

git-1.0
git-1.0.1
git-1.1
git-1.1.1
git-1.1.10
git-1.1.11
git-1.1.12
git-1.1.13
git-1.1.14
git-1.1.15
git-1.1.16
git-1.1.17
git-1.1.18
git-1.1.19
git-1.1.2
git-1.1.20
git-1.1.21
git-1.1.22
git-1.1.23
git-1.1.24
git-1.1.25
git-1.1.26
git-1.1.27
git-1.1.28
git-1.1.29
git-1.1.3
git-1.1.4
git-1.1.5
git-1.1.6
git-1.1.7
git-1.1.8
git-1.1.9
git-1.2.0
git-1.3.0
git-1.4.0
git-1.5.0
git-1.6.0-beta-1

git-2.*

git-2.0
git-2.0-beta-2
git-2.0-beta-3
git-2.0.1
git-2.0.2
git-2.0.3
git-2.0.4
git-2.1.0
git-2.2.0
git-2.2.1
git-2.3
git-2.3-beta-1
git-2.3-beta-2
git-2.3-beta-3
git-2.3-beta-4
git-2.3.1
git-2.3.2
git-2.3.3
git-2.3.4
git-2.3.5
git-2.4.0
git-2.4.1
git-2.4.2
git-2.4.3
git-2.4.4