CVE-2023-50770: Medium severity jenkins openid vulnerability
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that account, likely gaining administrator access to Jenkins.
Other sources
Jenkins OpenId Connect Authentication Plugin stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that account, likely gaining administrator access to Jenkins.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50770?
CVE-2023-50770 is classified as a critical vulnerability due to the risk of exposing plain text passwords of local accounts.
How do I fix CVE-2023-50770?
To fix CVE-2023-50770, update the Jenkins OpenId Connect Authentication Plugin to version 2.7 or later.
Who is affected by CVE-2023-50770?
CVE-2023-50770 affects users of Jenkins OpenId Connect Authentication Plugin versions 2.6 and earlier.
What type of attacks can be executed due to CVE-2023-50770?
Attackers with access to the Jenkins controller file system can potentially recover the plain text password of a local user account.
When was CVE-2023-50770 disclosed?
CVE-2023-50770 was publicly disclosed on December 13, 2023.