PT-2025-35780 · Jenkins · Jenkins Git Client Plugin+1
Daniel Beck
·
Published
2025-09-03
·
Updated
2025-09-08
·
CVE-2025-58458
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Git client Plugin versions 6.3.2 and earlier
Description
The Git URL field form validation responses differ based on whether the specified file path exists on the Jenkins controller when using the
amazon-s3 protocol with JGit. This allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.Recommendations
Upgrade Jenkins Git client Plugin to a version later than 6.3.2.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Git Client Plugin