Description
Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login.
Remediation
References
https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-2996
Related Vulnerabilities
CVE-2018-1999006 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-33948 Vulnerability in maven package com.liferay.portal:release.portal.bom
CVE-2017-16153 Vulnerability in npm package gaoxuyan
CVE-2021-3827 Vulnerability in maven package org.keycloak:keycloak-server-spi-private
CVE-2015-20110 Vulnerability in npm package generator-jhipster