CVE-2022-46683: Medium severity jenkins vulnerability
Published Dec 7, 2022
·Updated
Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkins.
Affected Software
1 affected component
jenkins Google Login Jenkins>=1.4<1.7
Event History
Dec 7, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Dec 12, 2022
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the Jenkins Google Login Plugin?
The vulnerability ID for the Jenkins Google Login Plugin is CVE-2022-46683.
2
What is the severity rating of CVE-2022-46683?
The severity rating of CVE-2022-46683 is medium (6.1).
3
How does the vulnerability in Jenkins Google Login Plugin affect users?
The vulnerability in Jenkins Google Login Plugin allows an attacker to trick users into visiting malicious websites.
4
Which versions of Jenkins Google Login Plugin are affected by this vulnerability?
Versions 1.4 through 1.6 of Jenkins Google Login Plugin are affected by this vulnerability.
5
How can users mitigate the vulnerability in Jenkins Google Login Plugin?
Users should update to a version higher than 1.7 to mitigate the vulnerability in Jenkins Google Login Plugin.