Description
An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4543 | An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session. |
Github GHSA |
GHSA-mcqx-wc2j-qx9v | GitHub Authentication Plugin session fixation vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-09-16T20:37:33.126Z
Reserved: 2019-02-06T00:00:00.000Z
Link: CVE-2019-1003019
No data.
Status : Modified
Published: 2019-02-06T16:29:00.920
Modified: 2024-11-21T04:17:45.080
Link: CVE-2019-1003019
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA