Vulnerabilities > Jenkins > Saml

DATE CVE VULNERABILITY TITLE RISK
2021-08-31 CVE-2021-21678 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Saml
Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
network
low complexity
jenkins CWE-352
8.8
2018-06-26 CVE-2018-1000602 Session Fixation vulnerability in Jenkins Saml
A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session.
network
jenkins CWE-384
4.3