Jenkins Project Jenkins Openid Plugin vulnerabilities
5 known vulnerabilities affecting jenkins_project/jenkins_openid_plugin.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2023-24444CRITICALCVSS 9.8≥ unspecified, ≤ 2.42023-01-26
CVE-2023-24444 [CRITICAL] CWE-404 CVE-2023-24444: Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login.
Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login.
cvelistv5nvd
CVE-2023-24446HIGHCVSS 8.8≥ unspecified, ≤ 2.42023-01-26
CVE-2023-24446 [HIGH] CWE-352 CVE-2023-24446: A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows at
A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to trick users into logging in to the attacker's account.
cvelistv5nvd
CVE-2023-24445MEDIUMCVSS 6.1≥ unspecified, ≤ 2.42023-01-26
CVE-2023-24445 [MEDIUM] CWE-601 CVE-2023-24445: Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legit
Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins.
cvelistv5nvd
CVE-2019-1003098MEDIUMCVSS 6.5vall versions as of 2019-04-032019-04-04
CVE-2019-1003098 [MEDIUM] CWE-352 CVE-2019-1003098: A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.De
A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server.
cvelistv5nvd
CVE-2019-1003099MEDIUMCVSS 6.5vall versions as of 2019-04-032019-04-04
CVE-2019-1003099 [MEDIUM] CWE-862 CVE-2019-1003099: A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doV
A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
cvelistv5nvd