Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
git git vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2021-21684
Jenkins Git Plugin 4.8.2 and previous versions does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.
Jenkins Git
7.4
CVSSv3
CVE-2021-34599
Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certificate validation by default, so it does not verify that the server provides a valid and trusted HTTPS certificate. Since the certif...
Codesys Git
5.4
CVSSv3
CVE-2020-2136
Jenkins Git Plugin 4.2.0 and previous versions does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.
Jenkins Git
6.5
CVSSv3
CVE-2022-38663
Jenkins Git Plugin 4.11.4 and previous versions does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePassword`) credentials binding.
Jenkins Git
8.8
CVSSv3
CVE-2022-36882
A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and previous versions allows malicious users to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.
Jenkins Git
7.5
CVSSv3
CVE-2022-36883
A missing permission check in Jenkins Git Plugin 4.11.3 and previous versions allows unauthenticated malicious users to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.
Jenkins Git
5.3
CVSSv3
CVE-2022-36884
The webhook endpoint in Jenkins Git Plugin 4.11.3 and previous versions provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.
Jenkins Git
7.3
CVSSv3
CVE-2022-31012
Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions before 2.37.1 lets Git for Windows' installer execute a binary into `C:\mingw64\bin\git.exe` by mistake. This only happens upon a fresh install, not when upgrading Git for...
Gitforwindows Git
7.5
CVSSv3
CVE-2021-46101
In Git for windows up to and including 2.34.1 when using git pull to update the local warehouse, git.cmd can be run directly.
Gitforwindows Git
7.5
CVSSv3
CVE-2022-30947
Jenkins Git Plugin 4.11.1 and previous versions allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents...
Jenkins Git
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »