CVE-2025-58458
MEDIUM4.3EPSS 0.11%Jenkins Git client Plugin file system information disclosure vulnerability
發布日:2025/9/3修改日:2025/11/5
描述
In Jenkins Git client Plugin 6.3.2 and earlier, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
受影響套件(1)
- Maven/org.jenkins-ci.plugins:git-clientfrom 0, < 6.3.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
參考連結(5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-58458
- PATCHhttps://github.com/jenkinsci/git-client-plugin
- WEBhttps://github.com/jenkinsci/git-client-plugin/commit/20090a86c3ebc72e5283c882de73e3a4459137bb
- WEBhttps://www.jenkins.io/security/advisory/2025-09-03/#SECURITY-3590
- WEBhttp://www.openwall.com/lists/oss-security/2025/09/03/4