A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.
https://github.com/advisories/GHSA-682g-c99v-9r2g
https://jenkins.io/security/advisory/2019-08-07/#SECURITY-795