Описание
Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after logging in.
Ссылки
- Mailing ListThird Party Advisory
- Issue TrackingPatchVendor Advisory
- Mailing ListThird Party Advisory
- Issue TrackingPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.13 (включая)
cpe:2.3:a:jenkins:gitlab_authentication:*:*:*:*:*:jenkins:*:*
EPSS
Процентиль: 18%
0.00059
Низкий
5.4 Medium
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-601
Связанные уязвимости
CVSS3: 5.4
github
почти 4 года назад
Open redirect vulnerability in Jenkins GitLab Authentication Plugin
EPSS
Процентиль: 18%
0.00059
Низкий
5.4 Medium
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-601