Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
| Software | From | Fixed in |
|---|---|---|
| jenkins / git_client | 3.0.0-rc | 3.0.0-rc.x |
| jenkins / git_client | - | 2.8.4.x |
org.jenkins-ci.plugins / git-client
|
- | 2.8.5 |