DescriptionDhananjay Arunesh
2020-04-01 10:58:15 UTC
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
Reference:
http://www.openwall.com/lists/oss-security/2019/09/12/2
Comment 1Dhananjay Arunesh
2020-04-01 10:59:21 UTC