Description
A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session.
Remediation
References
https://jenkins.io/security/advisory/2018-06-25/#SECURITY-916
Related Vulnerabilities
CVE-2017-18355 Vulnerability in npm package rendertron-middleware
CVE-2018-1000173 Vulnerability in maven package org.jenkins-ci.plugins:google-login
CVE-2018-1000177 Vulnerability in maven package org.jenkins-ci.plugins:s3
CVE-2021-20334 Vulnerability in npm package mongodb-js-metrics
CVE-2023-26475 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore