GHSA-rp82-xvg3-727c
Dashboard / Vulnerabilities / GHSA-rp82-xvg3-727c
Summary: Jenkins Google Login Plugin Session Fixation vulnerability
Details: A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session. Google Login Plugin 1.3.1 invalidates the previous session during login, and creates a new one.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-1000173, https://github.com/jenkinsci/google-login-plugin, https://jenkins.io/security/advisory/2018-04-16, http://www.securityfocus.com/bid/104210
Affected packages
Package
Name: org.jenkins-ci.plugins:google-login
Purl: pkg:maven/org.jenkins-ci.plugins/google-login
Affected ranges
Type: ECOSYSTEM
Events:
