GHSA-rf5q-8gx3-xqfc
Dashboard / Vulnerabilities / GHSA-rf5q-8gx3-xqfc
Summary: Cross-Site Request Forgery in Jenkins Git Plugin
Details: Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at a username/password credentials ID could trick a developer with job configuration permissions into following a link with a maliciously crafted Jenkins URL which would result in the Jenkins Git client sending the username and password to an attacker-controlled server.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-1000092, https://bugzilla.redhat.com/show_bug.cgi?id=1471053, https://jenkins.io/security/advisory/2017-07-10
Affected packages
Package
Name: org.jenkins-ci.plugins:git
Purl: pkg:maven/org.jenkins-ci.plugins/git
Affected ranges
Type: ECOSYSTEM
Events:
