Git

Vendor:

First CVE: Oct 5, 2017 · Active for 8 years

11
Total CVEs
More Total CVEs than 89% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Git over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2017
8 years ago
Most Recent CVE
Aug 23, 2022
1,431 days ago

CVE Severity & Scoring

Git11 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None6 (54.5%)
Unknown0 (0.0%)
Required5 (45.5%)
Privileges Required
Low3 (27.3%)
High0 (0.0%)
None8 (72.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repositor
Jul 27, 20227.538NOYES
A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to use an attacker-specified Git re
Jul 27, 20228.826NONO
Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at a username/password credentials
Oct 5, 20177.525NONO
Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local pat
May 17, 20227.524NONO
Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePass
Aug 23, 20226.522NONO
Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a build cause, resulting in a stored
Oct 6, 20216.121NONO
The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git
Jul 27, 20225.320NONO
A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.java, TFS2013GitRepositoryBrows
Jun 5, 20186.420NONO
An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network access to obtain a list of nod
Mar 13, 20185.320NONO
A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Gi
Feb 6, 20194.317NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Git

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.4.017.50.8%00
3.3.117.50.8%00
3.3.017.50.8%00
3.2.017.50.8%00
3.1.017.50.8%00
3.0.517.50.8%00
3.0.417.50.8%00
3.0.317.50.8%00
3.0.217.50.8%00
3.0.117.50.8%00
3.0.017.50.8%00
2.6.517.50.8%00
2.6.417.50.8%00
2.6.217.50.8%00
2.6.117.50.8%00
2.6.017.50.8%00
2.5.317.50.8%00
2.5.217.50.8%00
2.5.117.50.8%00
2.5.017.50.8%00