In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a trusted job, potentially gaining unauthorized access to external services.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jenkins
Jenkins openid Connect Provider |
|
CPEs | cpe:2.3:a:jenkins:openid_connect_provider:*:*:*:*:*:jenkins:*:* | |
Vendors & Products |
Jenkins
Jenkins openid Connect Provider |
Thu, 15 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 | |
Metrics |
cvssV3_1
|
Wed, 14 May 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a trusted job, potentially gaining unauthorized access to external services. | |
References |
|

Status: PUBLISHED
Assigner: jenkins
Published: 2025-05-14T20:35:54.646Z
Updated: 2025-05-15T13:35:32.601Z
Reserved: 2025-05-13T12:21:13.540Z
Link: CVE-2025-47884

Updated: 2025-05-15T13:35:26.736Z

Status : Analyzed
Published: 2025-05-14T21:15:59.363
Modified: 2025-06-12T13:48:38.967
Link: CVE-2025-47884

No data.