AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-24399

HIGH · CVSS 8.8 EPSS 0.54%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-01-22 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It affects Jenkins, F5.

CVE
CVE-2025-24399
Severity
HIGH
CVSS
8.8
EPSS
0.54%
Jenkins F5

Original NVD Description

Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in letter case, potentially gaining administrator access to Jenkins.

Related CVEs

Other vulnerabilities affecting the same vendor(s)