Known Vulnerabilities for Openid by Jenkins
Listed below are 5 of the newest known vulnerabilities associated with "Openid" by "Jenkins".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65635 json | Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers t... | Not Provided | 2026-07-30 | 2026-07-30 |
| CVE-2026-63687 json | Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without ex... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-59096 json | Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document from ... | Not Provided | 2026-07-02 | 2026-07-14 |
| CVE-2026-57817 json | The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hyb... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-54885 json | Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuth/Op... | Not Provided | 2026-07-30 | 2026-07-30 |
| CVE-2026-54603 json | OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-53661 json | Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity ... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-49757 json | Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via ... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-49478 json | Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions throu... | Not Provided | 2026-08-13 | 2026-08-15 |
| CVE-2026-49229 json | Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future... | Not Provided | 2026-07-07 | 2026-07-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jenkins | Openid | 2.4 | |||
| Application | Jenkins | Openid | 2.3 | |||
| Application | Jenkins | Openid | 2.2 | |||
| Application | Jenkins | Openid | 2.1.1 | |||
| Application | Jenkins | Openid | 2.1 | |||
| Application | Jenkins | Openid | 2.0 | |||
| Application | Jenkins | Openid | 1.8 | |||
| Application | Jenkins | Openid | 1.7 | |||
| Application | Jenkins | Openid | 1.6 | |||
| Application | Jenkins | Openid | 1.5 | |||
| Application | Jenkins | Openid | 1.4 | |||
| Application | Jenkins | Openid | 1.3 | |||
| Application | Jenkins | Openid | 1.2 | |||
| Application | Jenkins | Openid | 1.1 | |||
| Application | Jenkins | Openid | 1.0 | |||
| Application | Jenkins | Openid | - |