{"id":"GHSA-49hx-9mm2-7675","summary":"Jenkins OpenId Connect Authentication Plugin lacks audience claim validation","details":"Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token during its authentication flow, a value to verify the token is issued for the correct client.\n\nThis vulnerability may allow attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.\n\nOpenId Connect Authentication Plugin 4.355.v3a_fb_fca_b_96d4 checks the `aud` (Audience) claim of an ID Token during its authentication flow.","aliases":["CVE-2024-47806"],"modified":"2024-10-02T22:12:29.272348Z","published":"2024-10-02T18:31:32Z","database_specific":{"severity":"CRITICAL","nvd_published_at":"2024-10-02T16:15:10Z","github_reviewed":true,"cwe_ids":["CWE-287"],"github_reviewed_at":"2024-10-02T21:50:53Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47806"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2024-10-02/#SECURITY-3441%20(1)"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:oic-auth","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/oic-auth"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.355.v3a"}]}],"versions":["1.0","1.1","1.2","1.3","1.4","1.5","1.6","1.7","1.8","2.0.0","2.1","2.2","2.3","2.4","2.5","2.6","3.0","4.220.v22331f08e6a_3","4.223.v503b_9a_75a_8a_f","4.224.v62720cfa_026e","4.225.v03326773b_44b_","4.227.v36610663f760","4.228.v0c3e8682ff1f","4.229.vf736b_fec02f4","4.236.v4124503b_a_f88","4.238.v0021f710b_b_f4","4.239.v325750a_96f3b_","4.250.v5a_d993226437","4.257.v5360e8489e8b_","4.269.va_7526f34f306","4.279.vca_c1e2fdd24b_","4.284.v0cc21de03d37","4.290.v6f5e8da_e98b_2","4.297.vcddb_d8a_e4694","4.299.v5ca_eb_6a_f3e6d","4.303.v84089a_708ea_7","4.320.v23537cb_a_b_5c6","4.324.vfd49d010926b_","4.329.v994d3f265d68","4.330.v6fdfc07513e3","4.331.vd925b_f76f3a_c","4.340.ve70636c6590e","4.346.v10401f543622","4.350.v347c3b_8b_9d95","4.354.v321ce67a_1de8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-49hx-9mm2-7675/GHSA-49hx-9mm2-7675.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}