CVE Database
/

CVE-2025-47889

Back to search

CVE-2025-47889

Published: May 14, 2025

Modified: May 19, 2025

PUBLISHED

Description

In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.

VendorProductVersions

Jenkins Project

Jenkins WSO2 Oauth Plugin

affected
1.0

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now