CVE-2018-1000173
08.05.2018, 15:29
A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | google_login | 𝑥 ≤ 1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration