CVE-2022-36883
40Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 6.9%
from disclosure to weapon
Published on NVDJul 27
VulnCheck+1464d
exploitation probability
6.9%top 6% of all CVEs
observed exploitation
yesVulnCheck
A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.
Affected products
Jenkins project · Jenkins Git Plugin