Improper Authentication Affecting org.jenkins-ci.plugins:wso2id-oauth package, versions [0,]


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.06% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGJENKINSCIPLUGINS-10182222
  • published19 May 2025
  • disclosed14 May 2025
  • creditKevin Guerroudj

Introduced: 14 May 2025

NewCVE-2025-47889  (opens in a new tab)
CWE-1390  (opens in a new tab)

How to fix?

There is no fixed version for org.jenkins-ci.plugins:wso2id-oauth.

Overview

Affected versions of this package are vulnerable to Improper Authentication due to the improper validation of authentication claims from the WSO2 realm. An attacker can gain unauthorized access and impersonate any user by submitting any username and password combination, even for accounts that do not exist. Sessions created this way do not have any additional authorities, i.e., memberships in groups, and the impact of successfully creating a session this way depends on the authorization strategy and how it is configured.

CVSS Base Scores

version 4.0
version 3.1