Jenkins Gitlab Oauth vulnerabilities
2 known vulnerabilities affecting jenkins/gitlab_oauth.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-10371HIGHCVSS 7.5≤ 1.42019-08-07
CVE-2019-10371 [HIGH] CWE-384 CVE-2019-10371: A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSe
A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.
nvd
CVE-2019-10372MEDIUMCVSS 6.1≤ 1.42019-08-07
CVE-2019-10372 [MEDIUM] CWE-601 CVE-2019-10372: An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecu
An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users to a URL outside Jenkins after successful login.
nvd