Description
Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login.
Remediation
References
https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-2980
Related Vulnerabilities
CVE-2023-6394 Vulnerability in maven package io.quarkus:quarkus-smallrye-graphql-deployment
CVE-2023-46120 Vulnerability in maven package com.rabbitmq:amqp-client
CVE-2023-34092 Vulnerability in maven package org.webjars.npm:vite
CVE-2023-25571 Vulnerability in npm package @backstage/core-components
CVE-2021-20293 Vulnerability in maven package org.jboss.resteasy:resteasy-core