GHSA-mcqx-wc2j-qx9v
GitHub Security Advisory
GitHub Authentication Plugin session fixation vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.
Affected Packages
Maven
org.jenkins-ci.plugins:github-oauth
Affected versions:
0
(fixed in 0.31)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.