Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.
CVSS Metrics