CVE-2022-36881: High severity jenkins git vulnerability
A flaw was found in the Git-Client Jenkins plugin. The affected versions of the Jenkins Git client Plugin do not perform SSH host key verification when connecting to Git repositories via SSH, enabling Man-in-the-middle attacks.
Other sources
Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-36881?
CVE-2022-36881 has been classified as a high severity vulnerability due to its potential for Man-in-the-middle attacks.
How do I fix CVE-2022-36881?
To fix CVE-2022-36881, update the Jenkins Git Client Plugin to version 3.11.1 or later.
Which versions of the Jenkins Git Client Plugin are affected by CVE-2022-36881?
Versions 3.11.0 and earlier of the Jenkins Git Client Plugin are affected by CVE-2022-36881.
What type of vulnerability is CVE-2022-36881?
CVE-2022-36881 is a vulnerability that involves the lack of SSH host key verification allowing for potential Man-in-the-middle attacks.
Can CVE-2022-36881 impact my Jenkins environment?
Yes, CVE-2022-36881 can impact your Jenkins environment by leaving it vulnerable to Man-in-the-middle attacks when connecting to Git repositories.