CVE-2019-10371: Jenkins GitLab OAuth

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.

Affected products

  • Jenkins GitLab OAuth: up to and including 1.4

Published 2019-08-07. Last modified 2026-06-17.