GHSA-h23j-73ww-7594
GitHub Security Advisory
Session fixation vulnerability in Jenkins OpenId Connect Authentication Plugin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login. This allows attackers to use social engineering techniques to gain administrator access to Jenkins. OpenId Connect Authentication Plugin 4.421.v5422614eb_e0a_ invalidates the existing session on login.
Affected Packages
Maven
org.jenkins-ci.plugins:oic-auth
Affected versions:
0
(fixed in 4.421.v5422614eb)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 24, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.