OS Command Injection In org.jenkins-ci.plugins:git-client
Description
Improper Neutralization of Special Elements used in an OS Command in Jenkins Git Client Plugin Jenkins Git Client Plugin 2.8.4 and earlier did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 2.8.5 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4.