Description
Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.
Affected products
- Jenkins Project / Jenkins Git client Pluginunspecified – 3.11.0
- Jenkins Project / Jenkins Git client Plugin3.10.0.1 – 3.10.0.1