CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Jenkins 1Openid Connect Authentication Jun 17, 2026 Jan 22, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensiti...Show more |
1Jenkins 1Openid Connect Authentication Jun 17, 2026 Nov 13, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login. |
1Jenkins 1Openid Connect Authentication Jun 17, 2026 Oct 2, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrat...Show more |
1Jenkins 1Openid Connect Authentication Jun 17, 2026 Oct 2, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administr...Show more |
1Jenkins 1Openid Connect Authentication Jun 17, 2026 Dec 13, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks. |
1Jenkins 1Openid Connect Authentication Jun 17, 2026 Jan 26, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login. |
1Jenkins 1Openid Connect Authentication Jun 17, 2026 Feb 6, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlier in OicSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web...Show more |