Github Branch Source

Vendor:

First CVE: Oct 5, 2017 · Active for 8 years

8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.0
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Github Branch Source over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2017
8 years ago
Most Recent CVE
Jun 24, 2026
29 days ago

CVE Severity & Scoring

Github Branch Source8 CVEs
All CVEs352,101 CVEs
Medium
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low5 (62.5%)
High0 (0.0%)
None3 (37.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Ent
Jun 24, 20264.322NONO
A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specifi
Apr 29, 20264.321NONO
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to config
Jan 24, 20246.520NONO
GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan Credentials are corr
Oct 5, 20176.320NONO
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are e
Jan 24, 20245.317NONO
A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause J
Jun 5, 20184.316NONO
GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permission
Oct 5, 20174.316NONO
A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier allows attackers to connect to an attacker-specified URL.
Jan 24, 20244.315NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Github Branch Source

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.2.025.20.7%00
2.0.716.30.6%00
2.0.625.30.7%00
2.0.525.30.7%00
2.0.425.30.7%00
2.0.325.30.7%00
2.0.225.30.7%00
2.0.125.30.7%00
2.0.025.30.7%00
1.925.30.7%00
1.8.125.30.7%00
1.825.30.7%00
1.725.30.7%00
1.625.30.7%00
1.525.30.7%00
1.425.30.7%00
1.325.30.7%00
1.225.30.7%00
1.1025.30.7%00
1.125.30.7%00