CVE-2025-58458

MEDIUM

Jenkins Git client Plugin <6.3.2 - Info Disclosure

Title source: llm

Description

In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

Scores

CVSS v3 4.3
EPSS 0.0006
EPSS Percentile 16.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200 CWE-538
Status published

Affected Products (3)

jenkins/git_client < 6.1.3
jenkins/git_client
org.jenkins-ci.plugins/git-client < 6.3.3Maven

Timeline

Published Sep 03, 2025
Tracked Since Feb 18, 2026