CVE-2018-1000174: Medium severity jenkins vulnerability
An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1000174?
CVE-2018-1000174 is an open redirect vulnerability in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login.
How severe is CVE-2018-1000174?
CVE-2018-1000174 has a severity level of 6.1 (Medium).
Which software is affected by CVE-2018-1000174?
Jenkins Google Login Plugin versions 1.3 and older are affected by CVE-2018-1000174.
How can I fix CVE-2018-1000174?
To fix CVE-2018-1000174, update Jenkins Google Login Plugin to a version newer than 1.3.
Where can I find more information about CVE-2018-1000174?
More information about CVE-2018-1000174 can be found at the following references: http://www.securityfocus.com/bid/104211, https://jenkins.io/security/advisory/2018-04-16/