A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session. SAML Plugin 1.0.7 invalidates the previous session during login and creates a new one.
{ "nvd_published_at": "2018-06-26T17:29:00Z", "cwe_ids": [ "CWE-384" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-12-12T17:10:16Z" }