Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-53652


Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.


Published

2025-07-09T16:15:24.627

Last Modified

2025-07-18T18:03:14.117

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins git_parameter < 444.vca_b_84d3703c2 Yes

References