First published: Wed Dec 07 2022(Updated: )
Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkins.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Google Login | >=1.4<1.7 | |
>=1.4<1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Jenkins Google Login Plugin is CVE-2022-46683.
The severity rating of CVE-2022-46683 is medium (6.1).
The vulnerability in Jenkins Google Login Plugin allows an attacker to trick users into visiting malicious websites.
Versions 1.4 through 1.6 of Jenkins Google Login Plugin are affected by this vulnerability.
Users should update to a version higher than 1.7 to mitigate the vulnerability in Jenkins Google Login Plugin.