CVE-2022-46683Open Redirect in Project Jenkins Google Login Plugin

CWE-601Open Redirect5 documents5 sources
Severity
6.1MEDIUMNVD
EPSS
0.8%
top 26.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12

Description

Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkins.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5jenkins_project/jenkins_google_login_plugin1.4unspecified+1
NVDjenkins/google_login1.41.7

🔴Vulnerability Details

3
GHSA
Jenkins Google Login Plugin Open Redirect vulnerability2022-12-12
OSV
Jenkins Google Login Plugin Open Redirect vulnerability2022-12-12
CVEList
CVE-2022-46683: Jenkins Google Login Plugin 12022-12-07

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2022-12-072022-12-07
CVE-2022-46683 — Open Redirect | cvebase