GHSA-p89h-p4ph-4vj6

Suggest an improvement
Source
https://github.com/advisories/GHSA-p89h-p4ph-4vj6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-p89h-p4ph-4vj6/GHSA-p89h-p4ph-4vj6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p89h-p4ph-4vj6
Aliases
  • CVE-2025-47889
Published
2025-05-14T21:31:20Z
Modified
2025-05-16T15:42:09.162868Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials
Details

In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.

Database specific
{
    "nvd_published_at": "2025-05-14T21:15:59Z",
    "cwe_ids": [
        "CWE-1390"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2025-05-16T14:49:27Z"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:wso2id-oauth

Package

Name
org.jenkins-ci.plugins:wso2id-oauth
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/wso2id-oauth

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.0

Affected versions

1.*

1.0