Description
Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.
Remediation
References
https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-2982
Related Vulnerabilities
CVE-2023-46233 Vulnerability in maven package org.webjars.bowergithub.brix:crypto-js
CVE-2023-26474 Vulnerability in maven package org.xwiki.platform:xwiki-platform-legacy-oldcore
CVE-2022-24816 Vulnerability in maven package it.geosolutions.jaiext.jiffle:jt-jiffle-language
CVE-2023-31066 Vulnerability in maven package org.apache.inlong:manager-service
CVE-2023-31101 Vulnerability in maven package org.apache.inlong:manager-pojo