CVE-2025-58458
MEDIUM4.3EPSS 0.11%Jenkins Git client Plugin file system information disclosure vulnerability
Published: 9/3/2025Modified: 11/5/2025
Also known as:GHSA-g2pq-9jr7-w6gv
Description
In Jenkins Git client Plugin 6.3.2 and earlier, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
Affected packages (1)
- Maven/org.jenkins-ci.plugins:git-clientfrom 0, < 6.3.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-58458
- PATCHhttps://github.com/jenkinsci/git-client-plugin
- WEBhttps://github.com/jenkinsci/git-client-plugin/commit/20090a86c3ebc72e5283c882de73e3a4459137bb
- WEBhttps://www.jenkins.io/security/advisory/2025-09-03/#SECURITY-3590
- WEBhttp://www.openwall.com/lists/oss-security/2025/09/03/4