Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at a username/password credentials ID could trick a developer with job configuration permissions into following a link with a maliciously crafted Jenkins URL which would result in the Jenkins Git client sending the username and password to an attacker-controlled server.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Git | Jenkins | 0.1.0 (including) | 0.1.0 (including) |
Git | Jenkins | 0.2.0 (including) | 0.2.0 (including) |
Git | Jenkins | 0.3.0 (including) | 0.3.0 (including) |
Git | Jenkins | 0.4.0 (including) | 0.4.0 (including) |
Git | Jenkins | 0.5.0 (including) | 0.5.0 (including) |
Git | Jenkins | 0.6.0 (including) | 0.6.0 (including) |
Git | Jenkins | 0.7.0 (including) | 0.7.0 (including) |
Git | Jenkins | 0.7.1 (including) | 0.7.1 (including) |
Git | Jenkins | 0.7.2 (including) | 0.7.2 (including) |
Git | Jenkins | 0.7.3 (including) | 0.7.3 (including) |
Git | Jenkins | 0.8.0 (including) | 0.8.0 (including) |
Git | Jenkins | 0.8.1 (including) | 0.8.1 (including) |
Git | Jenkins | 0.8.2 (including) | 0.8.2 (including) |
Git | Jenkins | 0.9.0 (including) | 0.9.0 (including) |
Git | Jenkins | 0.9.1 (including) | 0.9.1 (including) |
Git | Jenkins | 0.9.2 (including) | 0.9.2 (including) |
Git | Jenkins | 1.0.0 (including) | 1.0.0 (including) |
Git | Jenkins | 1.0.1 (including) | 1.0.1 (including) |
Git | Jenkins | 1.1.0 (including) | 1.1.0 (including) |
Git | Jenkins | 1.1.1 (including) | 1.1.1 (including) |
Git | Jenkins | 1.1.2 (including) | 1.1.2 (including) |
Git | Jenkins | 1.1.3 (including) | 1.1.3 (including) |
Git | Jenkins | 1.1.4 (including) | 1.1.4 (including) |
Git | Jenkins | 1.1.5 (including) | 1.1.5 (including) |
Git | Jenkins | 1.1.6 (including) | 1.1.6 (including) |
Git | Jenkins | 1.1.7 (including) | 1.1.7 (including) |
Git | Jenkins | 1.1.8 (including) | 1.1.8 (including) |
Git | Jenkins | 1.1.9 (including) | 1.1.9 (including) |
Git | Jenkins | 1.1.10 (including) | 1.1.10 (including) |
Git | Jenkins | 1.1.11 (including) | 1.1.11 (including) |
Git | Jenkins | 1.1.12 (including) | 1.1.12 (including) |
Git | Jenkins | 1.1.13 (including) | 1.1.13 (including) |
Git | Jenkins | 1.1.14 (including) | 1.1.14 (including) |
Git | Jenkins | 1.1.15 (including) | 1.1.15 (including) |
Git | Jenkins | 1.1.16 (including) | 1.1.16 (including) |
Git | Jenkins | 1.1.17 (including) | 1.1.17 (including) |
Git | Jenkins | 1.1.18 (including) | 1.1.18 (including) |
Git | Jenkins | 1.1.19 (including) | 1.1.19 (including) |
Git | Jenkins | 1.1.20 (including) | 1.1.20 (including) |
Git | Jenkins | 1.1.21 (including) | 1.1.21 (including) |
Git | Jenkins | 1.1.22 (including) | 1.1.22 (including) |
Git | Jenkins | 1.1.23 (including) | 1.1.23 (including) |
Git | Jenkins | 1.1.24 (including) | 1.1.24 (including) |
Git | Jenkins | 1.1.25 (including) | 1.1.25 (including) |
Git | Jenkins | 1.1.26 (including) | 1.1.26 (including) |
Git | Jenkins | 1.1.27 (including) | 1.1.27 (including) |
Git | Jenkins | 1.1.28 (including) | 1.1.28 (including) |
Git | Jenkins | 1.1.29 (including) | 1.1.29 (including) |
Git | Jenkins | 1.2.0 (including) | 1.2.0 (including) |
Git | Jenkins | 1.3.0 (including) | 1.3.0 (including) |
Git | Jenkins | 1.4.0 (including) | 1.4.0 (including) |
Git | Jenkins | 1.5.0 (including) | 1.5.0 (including) |
Git | Jenkins | 1.6.0-beta-1 (including) | 1.6.0-beta-1 (including) |
Git | Jenkins | 2.0.0 (including) | 2.0.0 (including) |
Git | Jenkins | 2.0.0-alpha-1 (including) | 2.0.0-alpha-1 (including) |
Git | Jenkins | 2.0.0-alpha-2 (including) | 2.0.0-alpha-2 (including) |
Git | Jenkins | 2.0.0-beta-2 (including) | 2.0.0-beta-2 (including) |
Git | Jenkins | 2.0.0-beta-3 (including) | 2.0.0-beta-3 (including) |
Git | Jenkins | 2.0.1 (including) | 2.0.1 (including) |
Git | Jenkins | 2.0.2 (including) | 2.0.2 (including) |
Git | Jenkins | 2.0.3 (including) | 2.0.3 (including) |
Git | Jenkins | 2.0.4 (including) | 2.0.4 (including) |
Git | Jenkins | 2.1.0 (including) | 2.1.0 (including) |
Git | Jenkins | 2.2.0 (including) | 2.2.0 (including) |
Git | Jenkins | 2.2.1 (including) | 2.2.1 (including) |
Git | Jenkins | 2.2.2 (including) | 2.2.2 (including) |
Git | Jenkins | 2.2.3 (including) | 2.2.3 (including) |
Git | Jenkins | 2.2.4 (including) | 2.2.4 (including) |
Git | Jenkins | 2.2.5 (including) | 2.2.5 (including) |
Git | Jenkins | 2.2.6 (including) | 2.2.6 (including) |
Git | Jenkins | 2.2.7 (including) | 2.2.7 (including) |
Git | Jenkins | 2.2.8 (including) | 2.2.8 (including) |
Git | Jenkins | 2.2.9 (including) | 2.2.9 (including) |
Git | Jenkins | 2.2.10 (including) | 2.2.10 (including) |
Git | Jenkins | 2.2.11 (including) | 2.2.11 (including) |
Git | Jenkins | 2.2.12 (including) | 2.2.12 (including) |
Git | Jenkins | 2.3.0 (including) | 2.3.0 (including) |
Git | Jenkins | 2.3.0-beta-1 (including) | 2.3.0-beta-1 (including) |
Git | Jenkins | 2.3.0-beta-2 (including) | 2.3.0-beta-2 (including) |
Git | Jenkins | 2.3.0-beta-3 (including) | 2.3.0-beta-3 (including) |
Git | Jenkins | 2.3.0-beta-4 (including) | 2.3.0-beta-4 (including) |
Git | Jenkins | 2.3.1 (including) | 2.3.1 (including) |
Git | Jenkins | 2.3.2 (including) | 2.3.2 (including) |
Git | Jenkins | 2.3.3 (including) | 2.3.3 (including) |
Git | Jenkins | 2.3.4 (including) | 2.3.4 (including) |
Git | Jenkins | 2.3.5 (including) | 2.3.5 (including) |
Git | Jenkins | 2.4.0 (including) | 2.4.0 (including) |
Git | Jenkins | 2.4.1 (including) | 2.4.1 (including) |
Git | Jenkins | 2.4.2 (including) | 2.4.2 (including) |
Git | Jenkins | 2.4.3 (including) | 2.4.3 (including) |
Git | Jenkins | 2.4.4 (including) | 2.4.4 (including) |
Git | Jenkins | 2.5.0 (including) | 2.5.0 (including) |
Git | Jenkins | 2.5.0-beta-1 (including) | 2.5.0-beta-1 (including) |
Git | Jenkins | 2.5.0-beta-2 (including) | 2.5.0-beta-2 (including) |
Git | Jenkins | 2.5.0-beta-3 (including) | 2.5.0-beta-3 (including) |
Git | Jenkins | 2.5.0-beta-4 (including) | 2.5.0-beta-4 (including) |
Git | Jenkins | 2.5.0-beta-5 (including) | 2.5.0-beta-5 (including) |
Git | Jenkins | 2.5.1 (including) | 2.5.1 (including) |
Git | Jenkins | 2.5.2 (including) | 2.5.2 (including) |
Git | Jenkins | 2.5.3 (including) | 2.5.3 (including) |
Git | Jenkins | 2.6.0 (including) | 2.6.0 (including) |
Git | Jenkins | 2.6.1 (including) | 2.6.1 (including) |
Git | Jenkins | 2.6.2 (including) | 2.6.2 (including) |
Git | Jenkins | 2.6.2-beta-1 (including) | 2.6.2-beta-1 (including) |
Git | Jenkins | 2.6.2-beta-2 (including) | 2.6.2-beta-2 (including) |
Git | Jenkins | 2.6.4 (including) | 2.6.4 (including) |
Git | Jenkins | 2.6.5 (including) | 2.6.5 (including) |
Git | Jenkins | 3.0.0 (including) | 3.0.0 (including) |
Git | Jenkins | 3.0.0-beta-1 (including) | 3.0.0-beta-1 (including) |
Git | Jenkins | 3.0.0-beta-2 (including) | 3.0.0-beta-2 (including) |
Git | Jenkins | 3.0.1 (including) | 3.0.1 (including) |
Git | Jenkins | 3.0.2 (including) | 3.0.2 (including) |
Git | Jenkins | 3.0.2-beta-1 (including) | 3.0.2-beta-1 (including) |
Git | Jenkins | 3.0.2-beta-2 (including) | 3.0.2-beta-2 (including) |
Git | Jenkins | 3.0.3 (including) | 3.0.3 (including) |
Git | Jenkins | 3.0.4 (including) | 3.0.4 (including) |
Git | Jenkins | 3.0.5 (including) | 3.0.5 (including) |
Git | Jenkins | 3.1.0 (including) | 3.1.0 (including) |
Git | Jenkins | 3.2.0 (including) | 3.2.0 (including) |
Git | Jenkins | 3.3.0 (including) | 3.3.0 (including) |
Git | Jenkins | 3.3.1 (including) | 3.3.1 (including) |
Git | Jenkins | 3.4.0-alpha-1 (including) | 3.4.0-alpha-1 (including) |
Git | Jenkins | 3.4.0-alpha-4 (including) | 3.4.0-alpha-4 (including) |
Git | Jenkins | 3.4.0-beta-1 (including) | 3.4.0-beta-1 (including) |
Red Hat OpenShift Container Platform 3.6 | RedHat | atomic-openshift-0:3.6.173.0.21-1.git.0.f95b0e7.el7 | * |
Red Hat OpenShift Container Platform 3.6 | RedHat | fluentd-0:0.12.39-2.el7 | * |
Red Hat OpenShift Container Platform 3.6 | RedHat | jenkins-2-plugins-0:3.7.1502412812-1.el7 | * |
Red Hat OpenShift Container Platform 3.6 | RedHat | kibana-0:4.6.4-3.el7 | * |
Red Hat OpenShift Container Platform 3.6 | RedHat | rubygem-cool.io-0:1.5.1-1.el7 | * |
Red Hat OpenShift Container Platform 3.6 | RedHat | rubygem-excon-0:0.58.0-1.el7 | * |
Red Hat OpenShift Container Platform 3.6 | RedHat | rubygem-faraday-0:0.13.0-1.el7 | * |
Red Hat OpenShift Container Platform 3.6 | RedHat | rubygem-fluent-plugin-kubernetes_metadata_filter-0:0.29.0-1.el7 | * |
Red Hat OpenShift Container Platform 3.6 | RedHat | rubygem-fluent-plugin-viaq_data_model-0:0.0.5-1.el7 | * |
Red Hat OpenShift Container Platform 3.6 | RedHat | rubygem-i18n-0:0.8.6-1.el7 | * |
Red Hat OpenShift Container Platform 3.6 | RedHat | rubygem-systemd-journal-0:1.3.0-1.el7 | * |