Improper Neutralization of Special Elements used in an OS Command in Jenkins Git Client Plugin
Details
Jenkins Git Client Plugin 2.8.4 and earlier did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.