PT-2023-26194 · Jenkins · Jenkins Openshift Login Plugin+1

Kevin Guerroudj

+1

·

Published

2023-07-12

·

Updated

2023-07-20

·

CVE-2023-37947

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins OpenShift Login Plugin versions 1.1.0.227.v27e08dfb 1a 20 and earlier
Description The issue improperly determines the legitimacy of a redirect URL after login, allowing attackers to perform phishing attacks. This is achieved by having users visit a Jenkins URL that forwards them to a different site after successful authentication.
Recommendations For Jenkins OpenShift Login Plugin versions 1.1.0.227.v27e08dfb 1a 20 and earlier, update to version 1.1.0.230.v5d7030b f5432 or later, which only redirects to relative Jenkins URLs, mitigating the phishing attack risk.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-37947
GHSA-35GF-XJGF-96C5
RHSA-2024:0777
RHSA-2024:0778

Affected Products

Jenkins
Jenkins Openshift Login Plugin