Description
A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session.
Remediation
References
https://jenkins.io/security/advisory/2018-06-25/#SECURITY-916
Related Vulnerabilities
CVE-2020-7011 Vulnerability in npm package @elastic/app-search-javascript
CVE-2015-7501 Vulnerability in maven package org.apache.commons:commons-collections4
CVE-2011-5063 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2022-23615 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2019-10241 Vulnerability in maven package org.eclipse.jetty:jetty-server