MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2023-50770

CVSS 6.7v3.1pub. 2023-12-13upd. 2024-11-21

Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that account, likely gaining administrator access to Jenkins.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Jenkins Openid

    APP
    Jenkins
    ≤ 2.6
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
CI/CD
CWE
References

Related vulnerabilities

CVE-2023-24444CRITICAL9.8PL ✓same product

Jenkins OpenID Plugin: brak unieważnienia sesji przy logowaniu

CVE-2023-24446HIGH8.8same product

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to...

CVE-2023-24445MEDIUM6.1same product

Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately po...

CVE-2019-1003098MEDIUM6.5same product

A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorIm...

CVE-2019-1003099MEDIUM6.5same product

A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate fo...