Логотип exploitDog
bind:CVE-2025-47884
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-47884

Количество 2

Количество 2

nvd логотип

CVE-2025-47884

9 месяцев назад

In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a trusted job, potentially gaining unauthorized access to external services.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-q7c3-x7hm-qq72

9 месяцев назад

Jenkins OpenID Connect Provider Plugin Incorrectly Validates Crafted Build ID Tokens

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-47884

In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a trusted job, potentially gaining unauthorized access to external services.

CVSS3: 9.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-q7c3-x7hm-qq72

Jenkins OpenID Connect Provider Plugin Incorrectly Validates Crafted Build ID Tokens

CVSS3: 9.1
0%
Низкий
9 месяцев назад

Уязвимостей на страницу