Loading HuntDB...

GHSA-hw6x-2qwv-rxr7

GitHub Security Advisory

Improper Neutralization of Special Elements used in an OS Command in Jenkins Git Client Plugin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Jenkins Git Client Plugin 2.8.4 and earlier did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.

Affected Packages

Maven org.jenkins-ci.plugins:git-client
Affected versions: 0 (fixed in 2.8.5)

Related CVEs

Key Information

GHSA ID
GHSA-hw6x-2qwv-rxr7
Published
May 24, 2022 4:55 PM
Last Modified
June 28, 2022 10:28 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:git-client
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.