cbcvebase.
CVE-2023-50770
published 2023-12-13

CVE-2023-50770: Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format…

PriorityP433medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.29%
20.5th percentile
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that account, likely gaining administrator access to Jenkins.

Affected

10 ranges
VendorProductVersion rangeFixed in
jenkinsdeployment_dashboard_plugin
jenkinsdingding_json_pusher_plugin
jenkinshtmlresource_plugin
jenkinsnexus_platform_plugin
jenkinsopenid<= 2.6
jenkinsopenid_connect_authentication_plugin
jenkinspaaslane_estimate_plugin
jenkinsscriptler_plugin
jenkinssynopsys_rapid_scan_static_is_the_only_plugin
jenkins_projectjenkins_openid_connect_authentication_plugin<= 2.6
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.