First published: Wed Jul 27 2022(Updated: )
A flaw was found in the Git-Client Jenkins plugin. The affected versions of the Jenkins Git client Plugin do not perform SSH host key verification when connecting to Git repositories via SSH, enabling Man-in-the-middle attacks.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.plugins:git-client | <=3.11.0 | 3.11.1 |
Jenkins Git Client | <=3.11.0 | |
<=3.11.0 | ||
redhat/git-client | <3.11.1 | 3.11.1 |
redhat/jenkins | <2-plugins-0:4.10.1667388055-1.el8 | 2-plugins-0:4.10.1667388055-1.el8 |
redhat/jenkins | <2-plugins-0:4.8.1672842762-1.el8 | 2-plugins-0:4.8.1672842762-1.el8 |
redhat/jenkins | <2-plugins-0:4.9.1667460322-1.el8 | 2-plugins-0:4.9.1667460322-1.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)