Jenkins OpenID Connect Provider Plugin Incorrectly Validates Crafted Build ID Tokens
Critical severity
GitHub Reviewed
Published
May 14, 2025
to the GitHub Advisory Database
•
Updated May 16, 2025
Package
Affected versions
< 111.v29fd614b3617
Patched versions
111.v29fd614b_3617
Description
Published by the National Vulnerability Database
May 14, 2025
Published to the GitHub Advisory Database
May 14, 2025
Reviewed
May 16, 2025
Last updated
May 16, 2025
In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a trusted job, potentially gaining unauthorized access to external services.
References