Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.
| Software | From | Fixed in |
|---|---|---|
org.jenkins-ci.tools / git-parameter
|
- | 444.vca |
| jenkins / git_parameter | - | 444.vca_b_84d3703c2 |