CVE-2023-24444
EPSS 1.6%Session fixation vulnerability in Jenkins OpenID Plugin
Published: 1/26/2023Modified: 12/7/2024
Description
Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login.
Affected packages (1)
- Maven/org.jenkins-ci.plugins:openidfrom 0, <= 2.4