cbcvebase.
CVE-2024-47806
published 2024-10-02

CVE-2024-47806: Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to…

PriorityP351high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.63%
46.1th percentile
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.

Affected

8 ranges
VendorProductVersion rangeFixed in
jenkinscredentials_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinsopenid_connect_authentication< 4.355.v3a_fb_fca_b_96d44.355.v3a_fb_fca_b_96d4
jenkinsopenid_connect_authentication_plugin
jenkinsplain_credentials_plugin
jenkins_projectjenkins_openid_connect_authentication_plugin<= 4.354.v321ce67a_1de8
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.