Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.jenkins.plugins/oidc-provider
  4. ›
  5. CVE-2025-47884

CVE-2025-47884: Jenkins OpenID Connect Provider Plugin Incorrectly Validates Crafted Build ID Tokens

May 14, 2025 (updated May 16, 2025)

In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a trusted job, potentially gaining unauthorized access to external services.

References

  • github.com/advisories/GHSA-q7c3-x7hm-qq72
  • github.com/jenkinsci/oidc-provider-plugin
  • github.com/jenkinsci/oidc-provider-plugin/commit/29fd614b36171048ddc78a995ce44bd12bd7997d
  • github.com/jenkinsci/oidc-provider-plugin/releases/tag/111.v29fd614b_3617
  • nvd.nist.gov/vuln/detail/CVE-2025-47884
  • www.jenkins.io/security/advisory/2025-05-14/

Code Behaviors & Features

Detect and mitigate CVE-2025-47884 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 111.v29fd614b3617

Fixed versions

  • 111.v29fd614b3617

Solution

Upgrade to version 111.v29fd614b3617 or above.

Impact 9.1 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

Learn more about CVSS

Weakness

  • CWE-284: Improper Access Control

Source file

maven/io.jenkins.plugins/oidc-provider/CVE-2025-47884.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 19 Aug 2025 12:19:06 +0000.