CVE-2023-37946 is a high-severity vulnerability affecting Jenkins OpenShift Login Plugin versions 1.1.0.227.v27e08dfb_1a_20 and earlier, where the plugin fails to invalidate previous sessions upon a new login. This oversight allows an unauthenticated attacker to potentially hijack a user's session by tricking them into clicking a malicious link, leading to high impact on confidentiality, integrity, and availability. While the CVSS score is 8.8, indicating a significant risk, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or notable community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.0.230.v5d7030b_f5432CPE matchmatch criteria | cpe:2.3:a:jenkins:openshift_login:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.