CVE-2019-1003021: Jenkins Openid Connect Authentication
Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.
An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlier in OicSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client secret.
Affected products
- Jenkins Openid Connect Authentication: up to and including 1.4
Published 2019-02-06. Last modified 2026-06-17.