CVE-2019-10392: OS Command Injection
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
Other sources
Jenkins Git Client Plugin 2.8.4 and earlier did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10392?
CVE-2019-10392 is classified as a high severity vulnerability due to the potential for OS command injection.
How do I fix CVE-2019-10392?
To fix CVE-2019-10392, upgrade the Jenkins Git Client Plugin to version 2.8.5 or later.
What versions are affected by CVE-2019-10392?
CVE-2019-10392 affects Jenkins Git Client Plugin versions 2.8.4 and earlier, as well as version 3.0.0-rc.
What is OS command injection in CVE-2019-10392?
OS command injection in CVE-2019-10392 allows an attacker to execute arbitrary commands on the operating system via manipulated URL arguments.
Can CVE-2019-10392 be exploited remotely?
Yes, CVE-2019-10392 can potentially be exploited remotely if an attacker can control the input to the affected Git Client Plugin.