Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 295 respecto a la semana anterior
Críticas / altas1347▲ 81 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.55% | — | Jenkins Openid Connect Authentication | 22/1/2025 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in… | |
| Analizada | Alta (8.8) | 0.64% | — | Jenkins Openid Connect Authentication | 13/11/2024 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login. | |
| Analizada | Alta (8.1) | 0.63% | — | Jenkins Openid Connect Authentication | 2/10/2024 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins. | |
| Analizada | Alta (8.1) | 0.63% | — | Jenkins Openid Connect Authentication | 2/10/2024 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins. | |
| Analizada | Media (6.1) | 0.60% | — | Jenkins Openid Connect Authentication | 13/12/2023 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks. | |
| Modificada | Alta (8.8) | 1.2% | — | Jenkins Openid Connect Authentication | 26/1/2023 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login. | |
| Modificada | Media (4.3) | 1.1% | — | Jenkins Openid Connect Authentication | 6/2/2019 | 17/6/2026 | An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlier in OicSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client… |