Логотип exploitDog
bind:CVE-2025-58458
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-58458

Количество 2

Количество 2

nvd логотип

CVE-2025-58458

5 месяцев назад

In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-g2pq-9jr7-w6gv

5 месяцев назад

Jenkins Git client Plugin file system information disclosure vulnerability

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-58458

In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-g2pq-9jr7-w6gv

Jenkins Git client Plugin file system information disclosure vulnerability

CVSS3: 4.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу