Git Client Plugin Vulnerability in Jenkins by Jenkins
CVE-2025-58458
4.3MEDIUM
What is CVE-2025-58458?
The Git Client Plugin for Jenkins, versions 6.3.2 and earlier, is susceptible to a security flaw that allows attackers with Overall/Read permissions to determine the existence of specified file paths on the Jenkins controller file system. This issue arises when utilizing the 'amazon-s3' protocol for JGit. The plugin's validation mechanisms return different responses depending on whether the specified path exists, potentially exposing sensitive file system information.
Affected Version(s)
Jenkins Git client Plugin 0 <= 6.3.2