Loading HuntDB...

GHSA-mvq8-hgxh-4v2g

GitHub Security Advisory

Open redirect vulnerability in Jenkins GitLab Authentication Plugin

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP `Referer` header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after logging in.

This issue is caused by an incomplete fix of [SECURITY-796](https://www.jenkins.io/security/advisory/2019-08-07/#SECURITY-796).

Affected Packages

Maven org.jenkins-ci.plugins:gitlab-oauth
Affected versions: 0 (last affected: 1.13)

Related CVEs

Key Information

GHSA ID
GHSA-mvq8-hgxh-4v2g
Published
February 16, 2022 12:01 AM
Last Modified
October 27, 2023 4:23 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:gitlab-oauth
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.