Known vulnerabilities in OpenId Connect Authentication
Vendor:
Jenkins
Software:
OpenId Connect Authentication
Software CPE:
cpe:2.3:a:jenkins:openid_connect_authentication:*:*:*:*:*:*:*:*
Website:
https://jenkins.io/
Total vulnerabilities:
7
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
4.718
4.715
4.690
4.681
4.668
4.626
4.609
4.600
4.524
4.520
4.519
4.517
4.494
4.487
4.486
4.482
4.453.v4d7765c854f4
4.452.v2849b_d3945fa_
4.457
4.453
4.438.440
4.452
4.444
4.438
4.421.v5422614eb_e0a_
4.418.vccc7061f5b_6d
4.421
4.418
4.411
4.409
4.388
4.371
4.355.v3a_fb_fca_b_96d4
4.354.v321ce67a_1de8
4.355
4.354
4.350
4.346
4.340
4.331
4.330
4.329
4.324
4.320
4.303
4.299
4.297
4.290
4.284
4.279
4.269
4.257
4.250
4.239
4.238
4.236
4.229
4.228
4.227
4.225
4.224
4.223
3.0
2.6
2.5
2.4
2.3
2.2
2.1
2.0
1.8
1.7
1.6
1.5
1.4
1.3
1.2
1.1
1.0
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU103263 - Improper Handling of Case Sensitivity CVE-2025-24399 |
CWE-178 | Medium | 4.453.v4d7765c854f4 | 23.01.2025 |
SB2025012332 |
||
| #VU100592 - Session Fixation CVE-2024-52553 |
CWE-384 | High | 4.421.v5422614eb_e0a_ | 18.11.2024 |
SB2024111831 |
||
| #VU98068 - Improper Authentication CVE-2024-47807 |
CWE-287 | High | 4.355.v3a_fb_fca_b_96d4 | 07.10.2024 |
SB2024100725 |
||
| #VU98067 - Improper Authentication CVE-2024-47806 |
CWE-287 | High | 4.355.v3a_fb_fca_b_96d4 | 07.10.2024 |
SB2024100725 |
||
| #VU84456 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2023-50771 |
CWE-601 | Low | - | 15.12.2023 |
SB2023121516 |
||
| #VU84455 - Storing Passwords in a Recoverable Format CVE-2023-50770 |
CWE-257 | Low | - | 15.12.2023 |
SB2023121516 |
||
| #VU71506 - Session Fixation CVE-2023-24424 |
CWE-384 | High | 2.5 | 25.01.2023 |
SB2023012508 |