CVE-2024-47807: Jenkins Openid Connect Authentication

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.

Affected products

  • Jenkins Openid Connect Authentication: before 4.355.v3a_fb_fca_b_96d4 (fixed in 4.355.v3a_fb_fca_b_96d4)

Published 2024-10-02. Last modified 2026-06-17.