First published: Thu Jul 07 2022(Updated: )
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins | =1.0 | |
Jenkins | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5298 is a vulnerability in the Google Login Plugin versions 1.0 and 1.1 for Jenkins that allows malicious anonymous users to bypass security measures.
The Google Login Plugin versions 1.0 and 1.1 for Jenkins are affected by CVE-2015-5298.
CVE-2015-5298 allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain.
CVE-2015-5298 has a severity rating of medium with a score of 6.5.
To fix CVE-2015-5298, it is recommended to update the Google Login Plugin to a secure version.