CVE-2025-47884Improper Access Control in Project Jenkins Openid Connect Provider Plugin

Severity
9.1CRITICALNVD
EPSS
0.9%
top 23.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14

Description

In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a trusted job, potentially gaining unauthorized access to external services.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:LExploitability: 3.1 | Impact: 5.3

Affected Packages10 packages

🔴Vulnerability Details

2
OSV
Jenkins OpenID Connect Provider Plugin Incorrectly Validates Crafted Build ID Tokens2025-05-14
GHSA
Jenkins OpenID Connect Provider Plugin Incorrectly Validates Crafted Build ID Tokens2025-05-14

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2025-05-142025-05-14