Jenkins OpenShift Login Plugin session fixation vulnerability
High severity
GitHub Reviewed
Published
Jul 12, 2023
to the GitHub Advisory Database
•
Updated Nov 5, 2023
Package
Affected versions
< 1.1.0.230.v5d7030b
Patched versions
1.1.0.230.v5d7030b
Description
Published by the National Vulnerability Database
Jul 12, 2023
Published to the GitHub Advisory Database
Jul 12, 2023
Reviewed
Jul 12, 2023
Last updated
Nov 5, 2023
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the existing session on login.
This allows attackers to use social engineering techniques to gain administrator access to Jenkins.
OpenShift Login Plugin 1.1.0.230.v5d7030b_f5432 invalidates the existing session on login.
References