Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-49hx-9mm2-7675 | Jenkins OpenId Connect Authentication Plugin lacks audience claim validation |
Tue, 06 May 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins openid Connect Authentication |
|
| CPEs | cpe:2.3:a:jenkins:openid_connect_authentication:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins openid Connect Authentication |
Wed, 02 Oct 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins Project
Jenkins Project jenkins Openid Connect Authentication Plugin |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:jenkins_project:jenkins_openid_connect_authentication_plugin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins Openid Connect Authentication Plugin |
|
| Metrics |
cvssV3_1
|
Wed, 02 Oct 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-10-02T16:37:13.218Z
Reserved: 2024-10-01T20:59:52.484Z
Link: CVE-2024-47806
Updated: 2024-10-02T16:37:07.677Z
Status : Analyzed
Published: 2024-10-02T16:15:10.807
Modified: 2025-05-06T21:14:25.667
Link: CVE-2024-47806
No data.
OpenCVE Enrichment
No data.
Github GHSA