CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

jenkins

gitlab_authentication

4 known vulnerabilities · sorted by CVSS score

CVE-2020-2228
HIGH8.8

Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability.

jenkins / gitlab_authentication
Network
Published Jul 15, 2020
CVE-2022-27206
MEDIUM6.5

Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

jenkins / gitlab_authentication
Network
Published Mar 15, 2022
CVE-2022-25196
MEDIUM5.4

Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after logging in.

jenkins / gitlab_authentication
Network
Published Feb 15, 2022
CVE-2023-39153
MEDIUM5.4

A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to the attacker's account.

jenkins / gitlab_authentication
Network
Published Jul 26, 2023