Description

Jenkins is an application that monitors executions of repeated jobs, such as building a software project or jobs run by cron.

A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.

Remediation

Upgrade to the latest version of Jenkins Git Plugin

References

Related Vulnerabilities