GHSA-p487-39h9-hm84
Dashboard / Vulnerabilities / GHSA-p487-39h9-hm84
Summary: Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification
Details: The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-5298, https://github.com/jenkinsci/google-login-plugin, https://www.jenkins.io/security/advisory/2015-10-12, http://exfiltrated.com/research-CVE-2015-5298.php
Affected packages
Package
Name: org.jenkins-ci.plugins:google-login
Purl: pkg:maven/org.jenkins-ci.plugins/google-login
Affected ranges
Type: ECOSYSTEM
Events:
