CVE-2023-50770

MEDIUM

Jenkins Openid < 2.6 - Insufficiently Protected Credentials

Title source: rule

Description

Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that account, likely gaining administrator access to Jenkins.

Scores

CVSS v3 6.7
EPSS 0.0001
EPSS Percentile 1.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-522
Status published

Affected Products (2)

jenkins/openid < 2.6
org.jenkins-ci.plugins/oic-auth < 4.229.vf736bMaven

Timeline

Published Dec 13, 2023
Tracked Since Feb 18, 2026