CVE-2025-47889: Critical severity wso2 oauth plugin vulnerability
In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47889?
CVE-2025-47889 is categorized as a high severity vulnerability due to its potential to allow unauthenticated access to Jenkins controllers.
How do I fix CVE-2025-47889?
To address CVE-2025-47889, upgrade the WSO2 Oauth Plugin to version 1.1 or later, which includes necessary validation fixes.
What impact does CVE-2025-47889 have on my Jenkins installation?
CVE-2025-47889 allows unauthenticated attackers to log in with any credentials, potentially compromising your Jenkins environment.
Which versions of the WSO2 Oauth Plugin are affected by CVE-2025-47889?
CVE-2025-47889 affects WSO2 Oauth Plugin versions 1.0 and earlier.
Is my Jenkins instance safe if I do not use the WSO2 Oauth Plugin with CVE-2025-47889?
Yes, if you do not use the WSO2 Oauth Plugin, your Jenkins instance is not directly impacted by CVE-2025-47889.