GHSA-q7c3-x7hm-qq72

Suggest an improvement
Source
https://github.com/advisories/GHSA-q7c3-x7hm-qq72
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-q7c3-x7hm-qq72/GHSA-q7c3-x7hm-qq72.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q7c3-x7hm-qq72
Aliases
  • CVE-2025-47884
Published
2025-05-14T21:31:20Z
Modified
2025-05-16T20:31:23.882490Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L CVSS Calculator
Summary
Jenkins OpenID Connect Provider Plugin Incorrectly Validates Crafted Build ID Tokens
Details

In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a trusted job, potentially gaining unauthorized access to external services.

Database specific
{
    "nvd_published_at": "2025-05-14T21:15:59Z",
    "cwe_ids": [
        "CWE-284"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2025-05-16T14:42:45Z"
}
References

Affected packages

Maven / io.jenkins.plugins:oidc-provider

Package

Name
io.jenkins.plugins:oidc-provider
View open source insights on deps.dev
Purl
pkg:maven/io.jenkins.plugins/oidc-provider

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
111.v29fd614b_3617

Affected versions

18.*

18.v80b_cda_0cca_83

39.*

39.vb_a_d851b_03d30

41.*

41.v3ea_ce9dfd6d2

47.*

47.v182a_02f5b_771

60.*

60.v4b_9522d31cfb_

62.*

62.vd67c19f76766

79.*

79.v46f0066a_d813

89.*

89.v3dfb_6d89b_618

96.*

96.vee8ed882ec4d

Database specific

{
    "last_known_affected_version_range": "< 111.v29fd614b3617"
}