CVE-2025-47889
published 2025-05-14CVE-2025-47889: In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing…
PriorityP265critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.62%
45.6th percentile
In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | cadence_vmanager_plugin | — | — |
| jenkins | dingtalk_plugin | — | — |
| jenkins | environment_injector_plugin | — | — |
| jenkins | health_advisor_by_cloudbees_plugin | — | — |
| jenkins | matrix_authorization_strategy_plugin | — | — |
| jenkins | openid_connect_provider_plugin | — | — |
| jenkins | role-based_authorization_strategy_plugin | — | — |
| jenkins | wso2_oauth | <= 1.0 | — |
| jenkins | wso2_oauth_plugin | — | — |
| jenkins_project | jenkins_wso2_oauth_plugin | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials
ghsa·2025-05-14
CVE-2025-47889 [HIGH] CWE-1390 Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials
Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials
In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.
OSV
Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials
osv·2025-05-14
CVE-2025-47889 [HIGH] Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials
Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials
In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.
Jenkins
Jenkins Security Advisory 2025-05-14
vendor_jenkins·2025-05-14·CVSS 9.1
CVE-2025-47884 [CRITICAL] Jenkins Security Advisory 2025-05-14
Title: Jenkins Security Advisory 2025-05-14
Jenkins Security Advisory 2025-05-14
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Cadence vManager
Plugin
DingTalk
Plugin
Health Advisor by CloudBees
Plugin
OpenID Connect Provider
Plugin
WSO2 Oauth
Plugin
Descriptions
Insufficient validation of claims
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-14
Published