CVE-2019-10372

URL Redirection to Untrusted Site ('Open Redirect') in maven/org.jenkins-ci.plugins/gitlab-oauth

Identifiers

GHSA-pg59-2w33-8vmc, CVE-2019-10372

Package Slug

maven/org.jenkins-ci.plugins/gitlab-oauth

Vulnerability

URL Redirection to Untrusted Site ('Open Redirect')

Description

An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users to a URL outside Jenkins after successful login.

Affected Versions

All versions up to 1.4

Solution

Unfortunately, there is no solution available yet.

Last Modified

2023-03-06

source