Improper Validation of Specified Type of Input Affecting org.jenkins-ci.tools:git-parameter package, versions [,444.vca_b_84d3703c2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGJENKINSCITOOLS-10753750
  • published16 Jul 2025
  • disclosed9 Jul 2025
  • creditRoman Nahornyi

Introduced: 9 Jul 2025

NewCVE-2025-53652  (opens in a new tab)
CWE-1287  (opens in a new tab)

How to fix?

Upgrade org.jenkins-ci.tools:git-parameter to version 444.vca_b_84d3703c2 or higher.

Overview

org.jenkins-ci.tools:git-parameter is a git parameter Jenkins plugin.

Affected versions of this package are vulnerable to Improper Validation of Specified Type of Input via insufficient validation of submitted Git parameter values. An attacker can inject arbitrary values into Git parameters by submitting crafted input during the build process.

CVSS Base Scores

version 4.0
version 3.1