PT-2018-9344 · Jenkins · Jenkins Google Login Plugin+1
Postmanclient
+1
·
Publicado
2018-05-08
·
Atualizado
2022-05-14
·
CVE-2018-1000174
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Google Login Plugin versions 1.3 and older
Description
An open redirect issue exists in the GoogleOAuth2SecurityRealm.java file, allowing attackers to redirect users to an arbitrary URL after a successful login.
Recommendations
For Jenkins Google Login Plugin versions 1.3 and older, update to version 1.3.1 or newer, which only performs redirects to relative URLs, to resolve the issue.
Correção
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jenkins
Jenkins Google Login Plugin