Vulnerabilities > Jenkins > Openid Connect Authentication > 1.7

DATE CVE VULNERABILITY TITLE RISK
2023-12-13 CVE-2023-50771 Open Redirect vulnerability in Jenkins Openid Connect Authentication
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
network
low complexity
jenkins CWE-601
6.1
2023-01-26 CVE-2023-24424 Session Fixation vulnerability in Jenkins Openid Connect Authentication
Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login.
network
low complexity
jenkins CWE-384
8.8