Description
Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.
Remediation
References
https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-2982
Related Vulnerabilities
CVE-2019-10089 Vulnerability in maven package org.apache.jspwiki:jspwiki-war
CVE-2015-8854 Vulnerability in maven package org.webjars.bower:marked
CVE-2022-42128 Vulnerability in maven package com.liferay:com.liferay.headless.delivery.impl
CVE-2022-43414 Vulnerability in maven package org.jenkins-ci.plugins:nunit
CVE-2019-10080 Vulnerability in maven package org.apache.nifi:nifi-lookup-services-bundle