cbcvebase.
CVE-2025-58458
published 2025-09-03

CVE-2025-58458: In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path…

PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.29%
20.7th percentile
In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

Affected

7 ranges
VendorProductVersion rangeFixed in
jenkinsgit_client<= 6.1.3
jenkinsgit_client
jenkinsgit_client6.3.0 – 6.3.2
jenkinsgit_client_plugin
jenkinsopentelemetry_plugin
jenkinsurl_fields_in_git_plugin
jenkinswhile_use_of_this_protocol_in_git_client_plugin
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.