Логотип exploitDog
bind:CVE-2025-47889
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-47889

Количество 2

Количество 2

nvd логотип

CVE-2025-47889

9 месяцев назад

In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-p89h-p4ph-4vj6

9 месяцев назад

Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-47889

In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.

CVSS3: 9.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-p89h-p4ph-4vj6

Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials

CVSS3: 9.8
0%
Низкий
9 месяцев назад

Уязвимостей на страницу