CVE-2025-53652

Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of...

Basic Information

CVE State
PUBLISHED
Reserved Date
July 08, 2025
Published Date
July 09, 2025
Last Updated
November 04, 2025
Vendor
Jenkins Project
Product
Jenkins Git Parameter Plugin
Description
Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.

CVSS Scores

CVSS v3.1

8.2 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

SSVC Information

Exploitation
none
Automatable
Yes
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (2025-10-01 11:57:58 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-10-01 11:57:58 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel