PT-2019-11786 · Jenkins · Jenkins Git Client Plugin+1

·

CVE-2019-10392

·

Published

2019-09-12

·

Updated

2023-10-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Git Client Plugin versions 2.8.4 and earlier Jenkins Git Client Plugin version 3.0.0-rc
Description The issue results from improper restriction of values passed as URL arguments to an invocation of git ls-remote, leading to OS command injection.
Recommendations For Jenkins Git Client Plugin versions 2.8.4 and earlier, update to a version that properly restricts values passed as URL arguments to prevent OS command injection. For Jenkins Git Client Plugin version 3.0.0-rc, update to a version that properly restricts values passed as URL arguments to prevent OS command injection.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10392
GHSA-HW6X-2QWV-RXR7
RHSA-2020:2478

Affected Products

Jenkins
Jenkins Git Client Plugin