CVE-2017-1000092: Jenkins Git

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at a username/password credentials ID could trick a developer with job configuration permissions into following a link with a maliciously crafted Jenkins URL which would result in the Jenkins Git client sending the username and password to an attacker-controlled server.

Affected products

  • Jenkins Git: version 0.1.0 only; version 0.2.0 only; version 0.3.0 only; version 0.4.0 only; version 0.5.0 only; version 0.6.0 only; …

Published 2017-10-05. Last modified 2026-06-17.