CVE-2022-30947

high

Description

Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

References

https://www.jenkins.io/security/advisory/2022-05-17/#SECURITY-2478

http://www.openwall.com/lists/oss-security/2022/05/17/8

Details

Source: Mitre, NVD

Published: 2022-05-17

Updated: 2024-01-09

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High