Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-h23j-73ww-7594 | Session fixation vulnerability in Jenkins OpenId Connect Authentication Plugin |
Wed, 07 May 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins openid Connect Authentication
|
|
| CPEs | cpe:2.3:a:jenkins:openid_connect_authentication:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins openid Connect Authentication
|
Wed, 13 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins openid |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:jenkins:openid:-:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins openid |
|
| Metrics |
cvssV3_1
|
Wed, 13 Nov 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-11-13T21:38:06.118Z
Reserved: 2024-11-12T15:28:28.980Z
Link: CVE-2024-52553
Updated: 2024-11-13T21:37:56.357Z
Status : Analyzed
Published: 2024-11-13T21:15:29.473
Modified: 2025-05-07T14:15:02.663
Link: CVE-2024-52553
No data.
OpenCVE Enrichment
No data.
Github GHSA