CVE-2018-1000173

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/05/2018
Last modified:
13/06/2018

Description

A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:google_login:*:*:*:*:*:jenkins:*:* 1.3 (including)