CVE-2018-1000174

CVSS v3.0 6.1 (Medium)
61% Progress
CVSS v2.0 5.8 (Medium)
58% Progress
EPSS 0.08 % (34th)
0.08% Progress
Affected Products 1
Advisories 2

An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login.

Weaknesses
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2018-05-08 15:29:00
(6 years ago)
Updated Date
2018-06-13 14:53:10
(6 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Google Login for Jenkins 1.3 and prior versions cpe:2.3:a:jenkins:google_login::*:*:*:*:jenkins <= 1.3
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...