GHSA-682g-c99v-9r2g, CVE-2019-10371
maven/org.jenkins-ci.plugins/plugin
Session Fixation
A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.
All versions up to 1.4
Unfortunately, there is no solution available yet.
2023-03-06
source |