CVE-2022-36883 is a critical missing permission check vulnerability in Jenkins Git Plugin versions 4.11.3 and earlier. This flaw allows unauthenticated attackers to trigger builds and check out arbitrary commits from attacker-specified Git repositories. With a CVSS score of 7.5 (High) and an EPSS score indicating high exploitability, the vulnerability poses a significant risk of unauthorized code execution. While not currently on the KEV list or actively exploited, a Nuclei template exists, and its high FAUCET Risk Score suggests a strong potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.11.3CPE matchmatch criteria | cpe:2.3:a:jenkins:git:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.