PT-2025-5357 · Jenkins · Jenkins Openid Connect Authentication Plugin+1

James Nord

·

Published

2025-01-22

·

Updated

2025-01-22

·

CVE-2025-24399

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins OpenId Connect Authentication Plugin versions 4.452.v2849b d3945fa and earlier, except version 4.438.440.v3f5f201de5dc
Description The issue allows attackers to log in as any user by providing a username that differs only in letter case on Jenkins instances configured with a case-sensitive OpenID Connect provider, potentially gaining administrator access to Jenkins. This is due to the plugin treating usernames as case-insensitive.
Recommendations For Jenkins OpenId Connect Authentication Plugin versions 4.452.v2849b d3945fa and earlier, except version 4.438.440.v3f5f201de5dc, update to version 4.453.v4d7765c854f4 or later, which introduces an advanced configuration option to manage username case sensitivity with a default to case-sensitive. For versions that cannot be updated to 4.453.v4d7765c854f4 or later, consider configuring the OpenID Connect provider to be case-insensitive or restrict access to minimize the risk of exploitation until a patch is available.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2025-24399
GHSA-Q9CM-88JX-3VFW

Affected Products

Jenkins
Jenkins Openid Connect Authentication Plugin