Description
A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to the attacker's account.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/07/26/2
https://www.jenkins.io/security/advisory/2023-07-26/#SECURITY-2696
Related Vulnerabilities
CVE-2019-16869 Vulnerability in maven package io.netty:netty
CVE-2021-3461 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2018-1999024 Vulnerability in npm package mathjax
CVE-2019-10365 Vulnerability in maven package org.jenkins-ci.plugins:google-kubernetes-engine
CVE-2020-15500 Vulnerability in maven package org.webjars.npm:tileserver-gl