CVE-2025-58458 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path…
Medium CVSS: 4.3

CVE-2025-58458

In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
Vendor
Jenkins
Product
Git Client
CWE
CWE-200
Yayın Tarihi
2025-09-03 15:15:39
Güncelleme
2025-11-04 22:16:34
Source Identifier
jenkinsci-cert@googlegroups.com
KEV Date Added
-

Kategoriler

Referanslar