Lucene search

K
osvGoogleOSV:GHSA-RP82-XVG3-727C
HistoryMay 14, 2022 - 3:18 a.m.

Jenkins Google Login Plugin Session Fixation vulnerability

2022-05-1403:18:40
Google
osv.dev
9

0.001 Low

EPSS

Percentile

47.1%

A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session. Google Login Plugin 1.3.1 invalidates the previous session during login, and creates a new one.

0.001 Low

EPSS

Percentile

47.1%

Related for OSV:GHSA-RP82-XVG3-727C