GHSA-8pjw-fff6-3mjv
GitHub Security Advisory
Jenkins OpenId Connect Authentication Plugin lacks issuer claim validation
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token during its authentication flow, a value that identifies the Originating Party (IdP).
This vulnerability may allow attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.
OpenId Connect Authentication Plugin 4.355.v3a_fb_fca_b_96d4 checks the `iss` (Issuer) claim of an ID Token during its authentication flow when the Issuer is known.
Affected Packages
Maven
org.jenkins-ci.plugins:oic-auth
Affected versions:
0
(fixed in 4.355.v3a)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: July 1, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.