Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8pjw-fff6-3mjv Jenkins OpenId Connect Authentication Plugin lacks issuer claim validation
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 06 May 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins openid Connect Authentication
CPEs cpe:2.3:a:jenkins:openid_connect_authentication:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins openid Connect Authentication

Wed, 02 Oct 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Openid Connect Authentication Plugin
Weaknesses CWE-287
CPEs cpe:2.3:a:jenkins_project:jenkins_openid_connect_authentication_plugin:*:*:*:*:*:*:*:*
Vendors & Products Jenkins Project
Jenkins Project jenkins Openid Connect Authentication Plugin
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Oct 2024 15:45:00 +0000

Type Values Removed Values Added
Description Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-10-02T16:38:55.789Z

Reserved: 2024-10-01T20:59:52.484Z

Link: CVE-2024-47807

cve-icon Vulnrichment

Updated: 2024-10-02T16:38:26.231Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-02T16:15:10.857

Modified: 2025-05-06T21:13:38.657

Link: CVE-2024-47807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.