Security Advisory
CVE-2015-5298
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.