CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.1. It affects Jenkins.
CVE
CVE-2022-36881
Severity
HIGH
CVSS
8.1
EPSS
0.91%
Jenkins
Original NVD Description
Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.
Related CVEs
Other vulnerabilities affecting the same vendor(s)