Open redirect vulnerability in Jenkins GitLab Authentication Plugin
Moderate severity
GitHub Reviewed
Published
Feb 16, 2022
to the GitHub Advisory Database
•
Updated Oct 27, 2023
Description
Published by the National Vulnerability Database
Feb 15, 2022
Published to the GitHub Advisory Database
Feb 16, 2022
Reviewed
Dec 1, 2022
Last updated
Oct 27, 2023
Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP
Referer
header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after logging in.This issue is caused by an incomplete fix of SECURITY-796.
References