Description
A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session.
Remediation
References
https://jenkins.io/security/advisory/2018-06-25/#SECURITY-916
Related Vulnerabilities
CVE-2023-31007 Vulnerability in maven package org.apache.pulsar:pulsar-broker
CVE-2023-40178 Vulnerability in npm package @node-saml/node-saml
CVE-2018-1000605 Vulnerability in maven package org.jenkins-ci.plugins:collabnet
CVE-2020-13445 Vulnerability in maven package com.liferay:com.liferay.portal.template.velocity
CVE-2023-49382 Vulnerability in maven package com.jfinal:jfinal