Maven package
org.jenkins-ci.plugins/git-client
pkg:maven/org.jenkins-ci.plugins/git-client
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-67640 | — | < 6.4.1 | 6.4.1 | Dec 10, 2025 | Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS command | ||
| CVE-2025-58458 | — | < 6.3.3 | 6.3.3 | Sep 3, 2025 | In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read pe | ||
| CVE-2022-36881 | — | < 3.11.1 | 3.11.1 | Jul 27, 2022 | Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks. | ||
| CVE-2019-10392 | — | < 2.8.5 | 2.8.5 | Sep 12, 2019 | Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection. | ||
| CVE-2017-1000242 | Low | 3.3 | < 2.4.3 | 2.4.3 | Nov 1, 2017 | Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure |
- CVE-2025-67640Dec 10, 2025affected < 6.4.1fixed 6.4.1
Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS command
- CVE-2025-58458Sep 3, 2025affected < 6.3.3fixed 6.3.3
In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read pe
- CVE-2022-36881Jul 27, 2022affected < 3.11.1fixed 3.11.1
Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.
- CVE-2019-10392Sep 12, 2019affected < 2.8.5fixed 2.8.5
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
- affected < 2.4.3fixed 2.4.3
Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure