GHSA-pg59-2w33-8vmc
Dashboard / Vulnerabilities / GHSA-pg59-2w33-8vmc
Summary: Jenkins Gitlab Authentication Plugin Open Redirect vulnerability
Details: GitLab Authentication Plugin records the HTTP `Referer` header when the authentication process starts and redirects users to that URL when the user has finished logging in. This implements an open redirect, allowing malicious sites to implement a phishing attack, with users expecting they have just logged in to Jenkins.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-10372, https://github.com/jenkinsci/gitlab-oauth-plugin/commit/10059a4d4e121e0c3b13f6e6f74843565bb0b49a, https://jenkins.io/security/advisory/2019-08-07/#SECURITY-796, http://www.openwall.com/lists/oss-security/2019/08/07/1
Affected packages
Package
Name: org.jenkins-ci.plugins:gitlab-oauth
Purl: pkg:maven/org.jenkins-ci.plugins/gitlab-oauth
Affected ranges
Type: ECOSYSTEM
Events:
