ZeroHour

CVE-2022-25196

CVSS 3.1
5.4 medium
EPSS
<1%p52
Published
()
Modified
Description

Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after logging in.

Vendors
jenkins
Products
gitlab authentication
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.