CVE-2025-53652
published 2025-07-09CVE-2025-53652: Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered…
PriorityP346high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
EPSS
0.62%
45.5th percentile
Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | apica_loadtest_plugin | — | — |
| jenkins | applitools_eyes_plugin | — | — |
| jenkins | aqua_security_scanner_plugin | — | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | git_parameter | < 444.vca_b_84d3703c2 | 444.vca_b_84d3703c2 |
| jenkins | git_parameter_plugin | — | — |
| jenkins | html_publisher_plugin | — | — |
| jenkins | ibm_cloud_devops_plugin | — | — |
| jenkins | ifttt_build_notifier_plugin | — | — |
| jenkins | kryptowire_plugin | — | — |
| jenkins | nouvola_divecloud_plugin | — | — |
| jenkins | qmetry_test_management_plugin | — | — |
| jenkins | readyapi_functional_testing_plugin | — | — |
| jenkins | snitch_plugin | — | — |
| jenkins | statistics_gatherer_plugin | — | — |
| jenkins | testsigma_test_plan_run_plugin | — | — |
| jenkins | user1st_utester_plugin | — | — |
| jenkins | vaddy_plugin | — | — |
| jenkins | warrior_framework_plugin | — | — |
| jenkins | xooa_plugin | — | — |
| jenkins_project | jenkins_git_parameter_plugin | <= 439.vb_0e46ca_14534 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Jenkins
Jenkins Security Advisory 2025-07-09
vendor_jenkins·2025-07-09·CVSS 7.3
CVE-2025-53650 [HIGH] Jenkins Security Advisory 2025-07-09
Title: Jenkins Security Advisory 2025-07-09
Jenkins Security Advisory 2025-07-09
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Apica Loadtest
Plugin
Applitools Eyes
Plugin
Aqua Security Scanner
Plugin
Credentials Binding
Plugin
Dead Man's Snitch
Plugin
Git Parameter
Plugin
HTML Publisher
Pl
OSV
Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
osv·2025-07-09
CVE-2025-53652 [MEDIUM] Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
Jenkins Git Parameter Plugin implements a choice build parameter that lists the configured Git SCM’s branches, tags, pull requests, and revisions.
Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices.
This allows attackers with Item/Build permission to inject arbitrary values into Git parameters.
Git Parameter Plugin 444.vca_b_84d3703c2 validates that the Git parameter value submitted to the build matches one of the offered choices.
GHSA
Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
ghsa·2025-07-09
CVE-2025-53652 [MEDIUM] CWE-1287 Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
Jenkins Git Parameter Plugin implements a choice build parameter that lists the configured Git SCM’s branches, tags, pull requests, and revisions.
Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices.
This allows attackers with Item/Build permission to inject arbitrary values into Git parameters.
Git Parameter Plugin 444.vca_b_84d3703c2 validates that the Git parameter value submitted to the build matches one of the offered choices.
No detection rules found.
No public exploits indexed.
2025-07-09
Published