Description
Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login.
Remediation
References
https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-2996
Related Vulnerabilities
CVE-2013-1777 Vulnerability in maven package org.apache.geronimo.framework:geronimo-jmx-remoting
CVE-2015-6524 Vulnerability in maven package org.apache.activemq:activemq-osgi
CVE-2014-3623 Vulnerability in maven package org.apache.wss4j:wss4j
CVE-2023-4863 Vulnerability in npm package electron
CVE-2019-20343 Vulnerability in maven package org.codehaus.mojo:exec-maven-plugin