CVE-2019-10392
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
- Affected products
- Jenkins, Jenkins Git Client Plugin
- Jenkins Git Client
- ≤ 2.8.4, 3.0.0
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 25.8% (98th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2019-09-12
CVE-2019-10392 at NVD
5 known exploits for CVE-2019-10392
Proof-of-concept code and exploit modules indexed by Sploitus