Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing attackers with a previously configured SSH public key but lacking Overall/Read permission to access these repositories.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins git Server |
|
| CPEs | cpe:2.3:a:jenkins:git_server:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins git Server |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published: 2024-05-02T13:28:04.598Z
Updated: 2025-02-13T17:52:25.963Z
Reserved: 2024-04-30T20:53:08.612Z
Link: CVE-2024-34146
Updated: 2024-08-02T02:42:59.969Z
Status : Analyzed
Published: 2024-05-02T14:15:10.380
Modified: 2025-10-10T15:34:35.493
Link: CVE-2024-34146