CVE 2023-24424
Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login.
See the
CVE page on Mitre.org
for more details.
Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login.