CVE-2015-5298: Jenkins Google Login

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.

Affected products

  • Jenkins Google Login: version 1.0 only; version 1.1 only

Published 2022-07-07. Last modified 2026-06-17.