Описание
Session fixation vulnerability in Jenkins OpenId Connect Authentication Plugin
Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login. This allows attackers to use social engineering techniques to gain administrator access to Jenkins. OpenId Connect Authentication Plugin 4.421.v5422614eb_e0a_ invalidates the existing session on login.
Пакеты
Наименование
org.jenkins-ci.plugins:oic-auth
maven
Затронутые версииВерсия исправления
< 4.421.v5422614eb
4.421.v5422614eb
Связанные уязвимости
CVSS3: 8.8
nvd
около 1 года назад
Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.