Skip to main content

Vendor/product archive

jenkins / git_client CVEs

Beta · best-effort

6 CVEs tagged to jenkins / git_client0 Critical, 2 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2026-57282

Published Jun 24, 2026

Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-67640

Published Dec 10, 2025

Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58458

Published Sep 3, 2025

In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the contr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36881

Published Jul 27, 2022

Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10392

Published Sep 12, 2019

Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injec…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000242

Published Nov 1, 2017

Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1