Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p89h-p4ph-4vj6

Опубликовано: 14 мая 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 9.8

Описание

Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials

In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.

Пакеты

Наименование

org.jenkins-ci.plugins:wso2id-oauth

maven
Затронутые версииВерсия исправления

<= 1.0

Отсутствует

EPSS

Процентиль: 31%
0.00121
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1390
CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
9 месяцев назад

In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.

EPSS

Процентиль: 31%
0.00121
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1390
CWE-287