Showing 6 vulnerabilities on this page for Jenkins GitLab Authentication Plugin

Signals CISA KEV Ransomware Nuclei
Jenkins project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

CSRF vulnerability in GitLab Authentication Plugin

A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to the attacker's account.

CWE-352Jul 26, 2023
CVSS5.4v3.1EPSS0.696%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Client Secret stored in plain text by Jenkins GitLab Authentication Plugin

Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

CWE-311CWE-522Mar 15, 2022
CVSS6.5v3.1EPSS1.02%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Open redirect vulnerability in Jenkins GitLab Authentication Plugin

Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after logging in.

CWE-601Feb 15, 2022
CVSS5.4v3.1EPSS0.724%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin

Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability.

CWE-863Jul 15, 2020
CVSS8.8v3.1EPSS1.43%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Jenkins Gitlab Authentication Plugin Open Redirect vulnerability

An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users to a URL outside Jenkins after successful login.

CWE-601Aug 7, 2019
CVSS6.1v3.1EPSS0.965%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Jenkins Gitlab Authentication Plugin vulnerable to Session Fixation

A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.

CWE-384Aug 7, 2019
CVSS7.5v3.1EPSS1.31%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX