CVE-2025-24399
Published: Jan 22, 2025
Modified: Mar 18, 2025
Description
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in letter case, potentially gaining administrator access to Jenkins.
| Vendor | Product | Versions |
|---|---|---|
Jenkins Project | Jenkins OpenId Connect Authentication Plugin | unaffected 4.453.v4d7765c854f4 - < *unaffected 4.438.440.v3f5f201de5dc |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now