PT-2022-17136 · Jenkins · Jenkins Gitlab Authentication Plugin+1

James Nord

·

Published

2022-02-15

·

Updated

2023-11-03

·

CVE-2022-25196

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins GitLab Authentication Plugin versions 1.13 and earlier
Description The issue allows attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after logging in. This is caused by the plugin recording the HTTP Referer header as part of the URL query parameters when the authentication process starts.
Recommendations For Jenkins GitLab Authentication Plugin versions 1.13 and earlier, update to a version later than 1.13 to resolve the issue. As a temporary workaround, consider restricting access to the authentication process to minimize the risk of exploitation.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2022-25196
GHSA-MVQ8-HGXH-4V2G

Affected Products

Jenkins
Jenkins Gitlab Authentication Plugin