Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2pq-9jr7-w6gv

Опубликовано: 03 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Jenkins Git client Plugin file system information disclosure vulnerability

In Jenkins Git client Plugin 6.3.2 and earlier, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying amazon-s3 protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

Пакеты

Наименование

org.jenkins-ci.plugins:git-client

maven
Затронутые версииВерсия исправления

< 6.3.3

6.3.3

EPSS

Процентиль: 14%
0.00046
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-538

Связанные уязвимости

CVSS3: 4.3
nvd
5 месяцев назад

In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

EPSS

Процентиль: 14%
0.00046
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-538