PT-2023-26194 · Jenkins · Jenkins Openshift Login Plugin+1
Kevin Guerroudj
+1
·
Published
2023-07-12
·
Updated
2023-07-20
·
CVE-2023-37947
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins OpenShift Login Plugin versions 1.1.0.227.v27e08dfb 1a 20 and earlier
Description
The issue improperly determines the legitimacy of a redirect URL after login, allowing attackers to perform phishing attacks. This is achieved by having users visit a Jenkins URL that forwards them to a different site after successful authentication.
Recommendations
For Jenkins OpenShift Login Plugin versions 1.1.0.227.v27e08dfb 1a 20 and earlier, update to version 1.1.0.230.v5d7030b f5432 or later, which only redirects to relative Jenkins URLs, mitigating the phishing attack risk.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Openshift Login Plugin