Medium severity6.5NVD Advisory· Published Jul 7, 2022· Updated Jun 17, 2026
CVE-2015-5298
CVE-2015-5298
Description
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:google-loginMaven | >= 1.0, < 1.2 | 1.2 |
Affected products
4cpe:2.3:a:jenkins:google_login:1.0:*:*:*:*:jenkins:*:*+ 1 more
- cpe:2.3:a:jenkins:google_login:1.0:*:*:*:*:jenkins:*:*
- cpe:2.3:a:jenkins:google_login:1.1:*:*:*:*:jenkins:*:*
- Google Login Plugin/Google Login Plugindescription
Patches
Vulnerability mechanics
References
5- exfiltrated.com/research-CVE-2015-5298.phpnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-p487-39h9-hm84ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-5298ghsaADVISORY
- www.jenkins.io/security/advisory/2015-10-12/nvdVendor Advisory
- www.jenkins.io/security/advisory/2015-10-12ghsaWEB
News mentions
0No linked articles in our index yet.