CVE-2025-53652

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
09/07/2025
Last modified:
04/11/2025

Description

Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:git_parameter:*:*:*:*:*:jenkins:*:* 444.vca_b_84d3703c2 (excluding)