Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26516 | In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. |
Github GHSA |
GHSA-g2pq-9jr7-w6gv | Jenkins Git client Plugin file system information disclosure vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 08 Sep 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins git Client
|
|
| CPEs | cpe:2.3:a:jenkins:git_client:*:*:*:*:*:jenkins:*:* cpe:2.3:a:jenkins:git_client:6.2.0:*:*:*:*:jenkins:*:* |
|
| Vendors & Products |
Jenkins git Client
|
Thu, 04 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Jenkins Git client Plugin 6.3.2 and earlier, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. | In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. |
Wed, 03 Sep 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins git Client Plugin |
|
| Vendors & Products |
Jenkins
Jenkins git Client Plugin |
Wed, 03 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-538 |
|
| Metrics |
cvssV3_1
|
Wed, 03 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Jenkins Git client Plugin 6.3.2 and earlier, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-11-04T21:13:43.342Z
Reserved: 2025-09-02T12:44:16.983Z
Link: CVE-2025-58458
Updated: 2025-11-04T21:13:43.342Z
Status : Modified
Published: 2025-09-03T15:15:39.520
Modified: 2025-11-04T22:16:34.240
Link: CVE-2025-58458
No data.
OpenCVE Enrichment
Updated: 2025-09-03T20:26:54Z
EUVD
Github GHSA