Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openshift_login | Jenkins | * | 1.1.0.230.v5d7030b_f5432 (including) |
OCP-Tools-4.13-RHEL-8 | RedHat | jenkins-2-plugins-0:4.13.1706516346-1.el8 | * |
OCP-Tools-4.14-RHEL-8 | RedHat | jenkins-2-plugins-0:4.14.1706516441-1.el8 | * |
OpenShift Developer Tools and Services for OCP 4.11 | RedHat | jenkins-2-plugins-0:4.11.1706516946-1.el8 | * |
Such a scenario is commonly observed when: