The Jenkins project has issued a critical security advisory, describing vulnerabilities in five widely used plugins: Cadence vManager, DingTalk, Health Advisor by CloudBees, OpenID Connect Provider , and WSO2 Oauth.
See also: SonicWall SMA1000 vulnerability allows remote access

These vulnerabilities, which range in severity from medium to critical, could allow attackers to bypass authentication, execute malicious code, or gain unauthorized access to sensitive systems. Jenkins administrators are urged to take immediate action to mitigate the risks to their CI/CD infrastructures.
The alert highlights two critical vulnerabilities with very high CVSS scores:
- OpenID Connect Provider plugin (CVE-2025-47884, CVSS: 9.1)
- WSO2 Oauth plugin (CVE-2025-47889, CVSS: 9.8)
These vulnerabilities pose serious risks to Jenkins environments.
See also: Vulnerabilities fixed in Juniper, VMware and Zoom
Administrators are urged to update plugins to the patched versions immediately. For the DingTalk and WSO2 Oauth, the Jenkins project has not released patches, citing lack of maintenance or other limitations. Users may need to disable these plugins or implement workarounds, such as hardening network-level security or restricted access.

These vulnerabilities highlight the risks posed by unmaintained or misconfigured plugins in Jenkins, which is a fundamental component of DevOps pipelines.
The vulnerability in the WSO2 Oauth plugin particularly highlights the risks of lax authentication practices in security-critical environments, while the issue with OpenID Connect reveals the pitfalls that tampering with environment variables can cause in complex CI/CD setups.
The alert also ties into broader concerns around supply chain , with tools like Jenkins being prime targets. Malicious actors could exploit these vulnerabilities to inject malicious code, gain elevated privileges, or manipulate software build processes, with potential consequences for dependent systems and applications.
See also: Ivanti warns of two vulnerabilities in EPMM software
A relevant and critical point worth mentioning is that the security of CI/CD systems, such as Jenkins, from vulnerabilities, does not depend solely on the tool itself, but also on the health of its plugin ecosystem. Many of these plugins are developed by the community or third‑party providers, and when they are abandoned or not adequately maintained, they can become weak links.
Source: cybersecuritynews
