Loading HuntDB...

GHSA-h23j-73ww-7594

GitHub Security Advisory

Session fixation vulnerability in Jenkins OpenId Connect Authentication Plugin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login. This allows attackers to use social engineering techniques to gain administrator access to Jenkins. OpenId Connect Authentication Plugin 4.421.v5422614eb_e0a_ invalidates the existing session on login.

Affected Packages

Maven org.jenkins-ci.plugins:oic-auth
Affected versions: 0 (fixed in 4.421.v5422614eb)

Related CVEs

Key Information

GHSA ID
GHSA-h23j-73ww-7594
Published
November 13, 2024 9:30 PM
Last Modified
November 14, 2024 3:37 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:oic-auth
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.