Description
Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability.
Remediation
References
https://jenkins.io/security/advisory/2020-07-15/#SECURITY-1792
http://www.openwall.com/lists/oss-security/2020/07/15/5
Related Vulnerabilities
CVE-2016-8629 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2011-2730 Vulnerability in maven package org.springframework:spring-core
CVE-2023-31206 Vulnerability in maven package org.apache.inlong:manager-web
CVE-2021-46320 Vulnerability in npm package @openzeppelin/contracts
CVE-2023-30428 Vulnerability in maven package org.apache.pulsar:pulsar-broker