Git
Vendor:
First CVE: Oct 5, 2017 · Active for 8 years
11
Total CVEs
More Total CVEs than 89% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Git over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2017
8 years ago
Most Recent CVE
Aug 23, 2022
1,431 days ago
CVE Severity & Scoring
Git11 CVEs
64%
36%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None6 (54.5%)
Unknown0 (0.0%)
Required5 (45.5%)
Privileges Required
Low3 (27.3%)
High0 (0.0%)
None8 (72.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36883HIGH A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repositor | Jul 27, 2022 | 7.5 | 38 | NO | YES |
CVE-2022-36882HIGH A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to use an attacker-specified Git re | Jul 27, 2022 | 8.8 | 26 | NO | NO |
CVE-2017-1000092HIGH Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at a username/password credentials | Oct 5, 2017 | 7.5 | 25 | NO | NO |
CVE-2022-30947HIGH Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local pat | May 17, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-38663MEDIUM Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePass | Aug 23, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-21684MEDIUM Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a build cause, resulting in a stored | Oct 6, 2021 | 6.1 | 21 | NO | NO |
CVE-2022-36884MEDIUM The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git | Jul 27, 2022 | 5.3 | 20 | NO | NO |
CVE-2018-1000182MEDIUM A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.java, TFS2013GitRepositoryBrows | Jun 5, 2018 | 6.4 | 20 | NO | NO |
CVE-2018-1000110MEDIUM An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network access to obtain a list of nod | Mar 13, 2018 | 5.3 | 20 | NO | NO |
CVE-2019-1003010MEDIUM A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Gi | Feb 6, 2019 | 4.3 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Git
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.4.0 | 1 | 7.5 | 0.8% | 0 | 0 |
| 3.3.1 | 1 | 7.5 | 0.8% | 0 | 0 |
| 3.3.0 | 1 | 7.5 | 0.8% | 0 | 0 |
| 3.2.0 | 1 | 7.5 | 0.8% | 0 | 0 |
| 3.1.0 | 1 | 7.5 | 0.8% | 0 | 0 |
| 3.0.5 | 1 | 7.5 | 0.8% | 0 | 0 |
| 3.0.4 | 1 | 7.5 | 0.8% | 0 | 0 |
| 3.0.3 | 1 | 7.5 | 0.8% | 0 | 0 |
| 3.0.2 | 1 | 7.5 | 0.8% | 0 | 0 |
| 3.0.1 | 1 | 7.5 | 0.8% | 0 | 0 |
| 3.0.0 | 1 | 7.5 | 0.8% | 0 | 0 |
| 2.6.5 | 1 | 7.5 | 0.8% | 0 | 0 |
| 2.6.4 | 1 | 7.5 | 0.8% | 0 | 0 |
| 2.6.2 | 1 | 7.5 | 0.8% | 0 | 0 |
| 2.6.1 | 1 | 7.5 | 0.8% | 0 | 0 |
| 2.6.0 | 1 | 7.5 | 0.8% | 0 | 0 |
| 2.5.3 | 1 | 7.5 | 0.8% | 0 | 0 |
| 2.5.2 | 1 | 7.5 | 0.8% | 0 | 0 |
| 2.5.1 | 1 | 7.5 | 0.8% | 0 | 0 |
| 2.5.0 | 1 | 7.5 | 0.8% | 0 | 0 |