Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Postmanclient

Pesquisador dePostman
#47294de 56,326
5.8CVSS total
Vulnerabilidades · 1
PT-2018-9344
5.8
2018-05-08
Jenkins · Jenkins Google Login Plugin · CVE-2018-1000174
**Name of the Vulnerable Software and Affected Versions** Jenkins Google Login Plugin versions 1.3 and older **Description** An open redirect issue exists in the GoogleOAuth2SecurityRealm.java file, allowing attackers to redirect users to an arbitrary URL after a successful login. **Recommendations** For Jenkins Google Login Plugin versions 1.3 and older, update to version 1.3.1 or newer, which only performs redirects to relative URLs, to resolve the issue.