← Back to CVE List

CVE-2025-24399

Published: 2025-01-22T17:15Z
Last Modified: 2025-03-18T15:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in letter case, potentially gaining administrator access to Jenkins. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt