CVE-2017-1000092: Jenkins Git
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at a username/password credentials ID could trick a developer with job configuration permissions into following a link with a maliciously crafted Jenkins URL which would result in the Jenkins Git client sending the username and password to an attacker-controlled server.
Affected products
- Jenkins Git: version 0.1.0 only; version 0.2.0 only; version 0.3.0 only; version 0.4.0 only; version 0.5.0 only; version 0.6.0 only; …
Published 2017-10-05. Last modified 2026-06-17.