Description
Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkins.
Remediation
References
https://www.jenkins.io/security/advisory/2022-12-07/#SECURITY-2967
Related Vulnerabilities
CVE-2019-1003010 Vulnerability in maven package org.jenkins-ci.plugins:git
CVE-2011-5063 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2022-36097 Vulnerability in maven package org.xwiki.platform:xwiki-platform-attachment-ui
CVE-2019-10284 Vulnerability in maven package org.jenkins-ci.plugins:diawi-upload
CVE-2017-12174 Vulnerability in maven package org.apache.activemq:artemis-core-client