Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-36881


Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.


Published

2022-07-27T15:15:08.770

Last Modified

2024-11-21T07:13:58.447

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Primary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins git_client ≤ 3.11.0 Yes

References