GHSA-phh3-2p9m-w6j5
GitHub Security Advisory
Jenkins Subversion Partial Release Manager Plugin programmatically disables the fix for CVE-2016-3721
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically sets the Java system property `hudson.model.ParametersAction.keepUndefinedParameters` whenever a build is triggered from a release tag with the 'Svn-Partial Release Manager' SCM. Doing so disables the fix for [SECURITY-170](https://www.jenkins.io/security/advisory/2016-05-11/#arbitrary-build-parameters-are-passed-to-build-scripts-as-environment-variables) / CVE-2016-3721.
As of publication of this advisory, there is no fix.
Affected Packages
Maven
org.jenkins-ci.plugins:partial-release-manager
Affected versions:
0
(last affected: 1.0.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 5, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.