CVE-2019-10372Open Redirect in Jenkins Gitlab Oauth

CWE-601Open Redirect7 documents7 sources
Severity
6.1MEDIUMNVD
EPSS
0.1%
top 83.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 7
Latest updateMay 24

Description

An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users to a URL outside Jenkins after successful login.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
Jenkins Gitlab Authentication Plugin Open Redirect vulnerability2022-05-24
OSV
Jenkins Gitlab Authentication Plugin Open Redirect vulnerability2022-05-24
CVEList
CVE-2019-10372: An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 12019-08-07

💥Exploits & PoCs

1
Exploit-DB
Microsoft SharePoint Server 16.0.10372.20060 - 'GetXmlDataFromDataSource' Server-Side Request Forgery (SSRF)2021-06-11

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2019-08-072019-08-07
GitLab
CVE-2019-10372: An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users2019-08-07
CVE-2019-10372 — Open Redirect in Jenkins Gitlab Oauth | cvebase