cbcvebase.
CVE-2025-58458
published 2025-09-03

CVE-2025-58458: In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path…

PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.32%
24.7th percentile
In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

Affected

7 ranges
VendorProductVersion rangeFixed in
jenkinsgit_client<= 6.1.3—
jenkinsgit_client——
jenkinsgit_client6.3.0 – 6.3.2—
jenkinsgit_client_plugin——
jenkinsopentelemetry_plugin——
jenkinsurl_fields_in_git_plugin——
jenkinswhile_use_of_this_protocol_in_git_client_plugin——
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.