Jenkins Google Login Plugin CVE-2018-1000173 Session Fixation Vulnerability
BID:104210
CVE-2018-1000173 |Info
Jenkins Google Login Plugin CVE-2018-1000173 Session Fixation Vulnerability
| Bugtraq ID: | 104210 |
| Class: | Unknown |
| CVE: |
CVE-2018-1000173 |
| Remote: | Yes |
| Local: | No |
| Published: | May 16 2018 12:00AM |
| Updated: | May 16 2018 12:00AM |
| Credit: | Emeric Vernat |
| Vulnerable: |
Jenkins-Ci Google Login Plugin 1.3 |
| Not Vulnerable: |
Jenkins-Ci Google Login Plugin 1.3.1 |
Discussion
Jenkins Google Login Plugin CVE-2018-1000173 Session Fixation Vulnerability
Google Login Plugin for Jenkins is prone to a session-fixation vulnerability.
An attacker can hijack an arbitrary session and gain unauthorized access to the affected application.
Google Login Plugin version 1.3 and prior versions are vulnerable.
Google Login Plugin for Jenkins is prone to a session-fixation vulnerability.
An attacker can hijack an arbitrary session and gain unauthorized access to the affected application.
Google Login Plugin version 1.3 and prior versions are vulnerable.