Job impersonation via overrideable JOB_URL token claim
Published May 14, 2025 · Updated May 15, 2025
Improper access control in Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier lets remote authenticated users impersonate jobs. IdTokenCredentials builds the default sub claim from JOB_URL after Run.getEnvironment merges plugin-contributed values, so a conflicting job-controlled value enters the signed ID token. The attacker must be able to configure jobs on a controller with another plugin that permits environment-variable overrides; the forged job identity grants unauthorized access only where an external service trusts that subject.
Summary
What happened
Improper access control in Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier lets remote authenticated users impersonate jobs. IdTokenCredentials builds the default sub claim from JOB_URL after Run.getEnvironment merges plugin-contributed values, so a conflicting job-controlled value enters the signed ID token. The attacker must be able to configure jobs on a controller with another plugin that permits environment-variable overrides; the forged job identity grants unauthorized access only where an external service trusts that subject.
The record
- CVE
- CVE-2025-47884
- Published
- May 14, 2025
- Updated
- May 15, 2025
- Vendor
- Jenkins Project
- Product
- OpenID Connect Provider Plugin
- Classifications
- CWE-284, T1550.001
- Attack vector
- network
- Privileges
- authenticated
Timeline
How it unfolded
- May 14, 2025CVE publishedPublication date reported by the CVE source.
- May 15, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <=96.vee8ed882ec4d
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo