Known Vulnerabilities for Openid Connect Authentication by Jenkins
Listed below are 2 of the newest known vulnerabilities associated with "Openid Connect Authentication" by "Jenkins".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49757 json | Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via ... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-46412 json | @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Bet... | Not Provided | 2026-07-20 | 2026-07-20 |
| CVE-2026-44394 json | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propag... | Not Provided | 2026-05-28 | 2026-05-28 |
| CVE-2026-42604 json | Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= ... | Not Provided | 2026-06-12 | 2026-06-15 |
| CVE-2026-33318 json | Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can e... | Not Provided | 2026-04-24 | 2026-04-25 |
| CVE-2026-27962 json | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vul... | Not Provided | 2026-03-16 | 2026-07-20 |
| CVE-2026-13089 json | OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm all... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2023-24424 json | Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login. | 8.8 - HIGH | 2023-01-26 | 2023-02-03 |
| CVE-2019-1003021 json | An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlier in ... | 4.3 - MEDIUM | 2019-02-06 | 2023-10-25 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jenkins | Openid Connect Authentication | 1.4 |