Description
Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login.
Remediation
References
https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-2996
Related Vulnerabilities
CVE-2023-46998 Vulnerability in maven package org.webjars.bower:bootbox.js
CVE-2021-41184 Vulnerability in maven package org.webjars.npm:jquery-ui
CVE-2023-24445 Vulnerability in maven package org.jenkins-ci.plugins:openid
CVE-2023-41037 Vulnerability in maven package org.webjars.npm:github-com-openpgpjs-openpgpjs
CVE-2020-16024 Vulnerability in maven package org.webjars.npm:electron