Loading HuntDB...

GHSA-phh3-2p9m-w6j5

GitHub Security Advisory

Jenkins Subversion Partial Release Manager Plugin programmatically disables the fix for CVE-2016-3721

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically sets the Java system property `hudson.model.ParametersAction.keepUndefinedParameters` whenever a build is triggered from a release tag with the 'Svn-Partial Release Manager' SCM. Doing so disables the fix for [SECURITY-170](https://www.jenkins.io/security/advisory/2016-05-11/#arbitrary-build-parameters-are-passed-to-build-scripts-as-environment-variables) / CVE-2016-3721.

As of publication of this advisory, there is no fix.

Affected Packages

Maven org.jenkins-ci.plugins:partial-release-manager
Affected versions: 0 (last affected: 1.0.1)

Related CVEs

Key Information

GHSA ID
GHSA-phh3-2p9m-w6j5
Published
May 2, 2024 3:30 PM
Last Modified
July 3, 2024 8:11 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:partial-release-manager
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 5, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.