Описание
Improper Neutralization of Special Elements used in an OS Command in Jenkins Git Client Plugin
Jenkins Git Client Plugin 2.8.4 and earlier did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
Пакеты
Наименование
org.jenkins-ci.plugins:git-client
maven
Затронутые версииВерсия исправления
<= 2.8.4
2.8.5
Связанные уязвимости
CVSS3: 8.8
redhat
больше 6 лет назад
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
CVSS3: 8.8
nvd
больше 6 лет назад
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.