Lucene search

K
osvGoogleOSV:GHSA-4PJX-86PG-X4J5
HistoryMay 14, 2022 - 3:07 a.m.

Jenkins SAML Plugin Session Fixation vulnerability

2022-05-1403:07:02
Google
osv.dev
4

0.001 Low

EPSS

Percentile

32.0%

A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session. SAML Plugin 1.0.7 invalidates the previous session during login and creates a new one.

0.001 Low

EPSS

Percentile

32.0%

Related for OSV:GHSA-4PJX-86PG-X4J5