CVE-2025-47889: Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials
(updated )
In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the “WSO2 Oauth” security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-47889 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →