Description
A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session.
Remediation
References
https://jenkins.io/security/advisory/2018-06-25/#SECURITY-916
Related Vulnerabilities
CVE-2017-7660 Vulnerability in maven package org.apache.solr:solr-core
CVE-2020-11023 Vulnerability in npm package jquery
CVE-2023-50422 Vulnerability in maven package com.sap.cloud.security:spring-security
CVE-2019-10455 Vulnerability in maven package org.jenkins-ci.plugins:icescrum
CVE-2022-25167 Vulnerability in maven package org.apache.flume.flume-ng-sources:flume-jms-source