First published: Tue Jun 26 2018(Updated: )
A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.plugins:saml | <=1.0.6 | 1.0.7 |
Jenkins SAML | <=1.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-1000602.
The title of this vulnerability is 'A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java'.
The severity of CVE-2018-1000602 is medium (5.9).
This vulnerability affects Jenkins SAML Plugin version 1.0.6 and earlier.
Unauthorized attackers can exploit this vulnerability to impersonate other users if they can control the pre-authentication session.