Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after logging in.
References
Link Resource
http://www.openwall.com/lists/oss-security/2022/02/15/2 Mailing List Third Party Advisory
https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-1833 Issue Tracking Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jenkins

Published: 2022-02-15T16:11:26

Updated: 2023-10-24T14:19:57.021Z

Reserved: 2022-02-15T00:00:00


Link: CVE-2022-25196

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-02-15T17:15:10.537

Modified: 2023-11-03T16:24:45.253


Link: CVE-2022-25196

JSON object: View

cve-icon Redhat Information

No data.

CWE