-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:wso2id-oauth | maven | <= 1.0 |
The vulnerability stems from missing session invalidation during login. In Jenkins plugin architecture, authentication flows typically involve a SecurityRealm implementation. The doFinishLogin method (or equivalent) in OAuth handlers is where session management occurs. The advisory explicitly states existing sessions aren't invalidated, which would manifest in this critical authentication callback function. The confidence is high because session fixation vulnerabilities in Jenkins plugins are typically rooted in SecurityRealm implementations' login handlers, and the described behavior matches this pattern.
Ongoing coverage of React2Shell