Jenkins Gitlab Authentication Plugin Open Redirect vulnerability
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Dec 20, 2023
Description
Published by the National Vulnerability Database
Aug 7, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Mar 3, 2023
Last updated
Dec 20, 2023
GitLab Authentication Plugin records the HTTP
Referer
header when the authentication process starts and redirects users to that URL when the user has finished logging in.This implements an open redirect, allowing malicious sites to implement a phishing attack, with users expecting they have just logged in to Jenkins.
References