{"id":"CVE-2023-50770","aliases":[],"url":"https://o3.security/vulnerability/CVE-2023-50770","summary":"Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with…","details":"Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that account, likely gaining administrator access to Jenkins.","published":"2023-12-13T17:30:17.513Z","modified":"2025-02-13T17:19:34.765Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://www.jenkins.io/security/advisory/2023-12-13/#SECURITY-3168"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/12/13/4"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2025-02-13T17:19:34.765Z"}}