Description
Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1559 | Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login. |
Github GHSA |
GHSA-hjh8-9gxh-cx4x | Jenkins CAS Plugin Session Fixation vulnerability |
References
History
Thu, 23 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-01-23T15:57:28.000Z
Reserved: 2023-05-16T10:55:43.520Z
Link: CVE-2023-32997
Updated: 2024-08-02T15:32:46.498Z
Status : Modified
Published: 2023-05-16T17:15:12.067
Modified: 2025-01-23T16:15:30.483
Link: CVE-2023-32997
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA