Database/Control plane, storage & DevOps
Jenkins (Git Parameter plugin): Git parameter value is not validated against the offered choices
CVSS 8.2CVE-2025-53652Control plane, storage & DevOpscurated
Impact
Git parameter value is not validated against the offered choices -> injection of arbitrary values into builds
Who can reach it
Network (remote)
What to do
Control-plane: plugin upgrade
References
Related entries
- Foreman: command injection in the errors:fetch_log rake task escalates a scoped sudo grant to full code executionCVE-2026-12540 · Foreman / Red Hat Satellite (foreman-rake errors:fetch_log task)High
- Foreman / Red Hat Satellite: shell injection via foreman-rake db:dump and db:import_dump pathsCVE-2026-12541 · Foreman / Red Hat Satellite (foreman-rake db:dump and db:import_dump tasks)High
- IBM AIX and PowerVM VIOS: improper authentication allows remote access to NFS exportsCVE-2026-16686 · IBM AIX / PowerVM VIOS NFS server (export authentication)High
- Cisco Intersight Device Connector for Nutanix Prism Central: The device connector exposes an unauthenticated APICVE-2026-5944 · Cisco Intersight Device Connector for Nutanix Prism CentralHigh
- OpenChoreo Backstage backend: hardcoded auth bypass exposes /api/* to unauthenticated callersCVE-2026-73666 · OpenChoreo Backstage backend (default auth policy)High
- HPE OneView: remotely exploitable session hijacking against the infrastructure management consoleCVE-2026-76718 · HPE OneView (web interface, session handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.