Vulnerability Description
Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Git Parameter | < 444.vca_b_84d3703c2 |
Related Weaknesses (CWE)
References
- https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3419Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/07/09/4
FAQ
What is CVE-2025-53652?
CVE-2025-53652 is a vulnerability with a CVSS score of 8.2 (HIGH). Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Buil...
How severe is CVE-2025-53652?
CVE-2025-53652 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-53652?
Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Git Parameter.