CVE-2022-30947

Description

Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controllers file system using local paths as SCM URLs, obtaining limited information about other projects SCM contents.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
1.568

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-30947 are fixed in Jenkins - repo 1.15.0Windows
Vulnerabilities CVE-2022-30949,CVE-2022-30947 are fixed in Jenkins - git 4.11.2Windows
Vulnerabilities CVE-2022-30947 are fixed in Jenkins - repo for Linux 1.15.0Linux
Vulnerabilities CVE-2022-30949,CVE-2022-30947 are fixed in Jenkins - git for Linux 4.11.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234