Back to search
CVE-2025-53652
Published: Jul 9, 2025
Modified: Nov 4, 2025
PUBLISHED
Description
Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.
| Vendor | Product | Versions |
|---|---|---|
Jenkins Project | Jenkins Git Parameter Plugin | affected 0 - <= 439.vb_0e46ca_14534 |
References
Jenkins Security Advisory 2025-07-09
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now