Vulnerability GHSA-g2pq-9jr7-w6gv
Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 year ago
September 03, 2025 at 03:30 PM UTC
Jenkins Git client Plugin file system information disclosure vulnerability
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1
Summary
Jenkins Git client Plugin file system information disclosure vulnerability
Details
In Jenkins Git client Plugin 6.3.2 and earlier, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying amazon-s3 protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 months ago
Jenkins Git client Plugin has an OS command injection vulnerability on agents
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.5.0 - 6.6.0 GHSA-wp5x-hrrw-6r4g
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.5.0 - 6.6.0 GHSA-wp5x-hrrw-6r4g
Medium Risk
9 months ago
Jenkins Git client Plugin has an OS command injection vulnerability on agents in Git client Plugin
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.4.0 GHSA-v8hg-m323-jvjq
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.10.1 and 3.12.4 - 4.7.0 and 6.0.0 and 6.2.0 - 6.2.1 and 6.4.0 GHSA-v8hg-m323-jvjq
Medium Risk
4 years ago
Jenkins Git client plugin 3.11.0 does not perform SSH host key verification
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.11.0 GHSA-cm7j-p8hc-97vj
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 and 2.9.0 - 3.2.1 and 3.5.0 - 3.6.0 and 3.8.0 - 3.11.0 GHSA-cm7j-p8hc-97vj
High Risk
4 years ago
Improper Neutralization of Special Elements used in an OS Command in Jenkins Git Client Plugin
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 GHSA-hw6x-2qwv-rxr7
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 and 2.5.0 - 2.6.0 and 2.7.4 GHSA-hw6x-2qwv-rxr7
Low Risk
4 years ago
Insecure temporary file usage in Jenkins Git Client Plugin
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 GHSA-fcxw-hhxq-48wx
1.2.0 - 1.3.0 and 1.5.0 - 1.5.1 and 1.7.0 - 1.8.1 and 1.11.0 - 1.15.0 and 1.16.1 - 1.18.0 and 1.20.0 and 1.20.2 - 2.3.0 GHSA-fcxw-hhxq-48wx
Impacted packages
Timeline
Published
1 year ago
September 03, 2025 at 03:30 PM UTC
Last Modified
10 months ago
November 05, 2025 at 08:52 PM UTC