Description
Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login.
Remediation
References
https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-2987
Related Vulnerabilities
CVE-2023-31206 Vulnerability in maven package org.apache.inlong:manager-service
CVE-2023-37943 Vulnerability in maven package org.jenkins-ci.plugins:active-directory
CVE-2019-25028 Vulnerability in maven package com.vaadin:vaadin-server
CVE-2020-2252 Vulnerability in maven package org.jenkins-ci.plugins:mailer
CVE-2019-1003089 Vulnerability in maven package ren.helloworld:upload-pgyer