CVE-2023-24424: High severity jenkins openid connect authentication plugin vulnerability
Published Jan 24, 2023
·Updated
Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login.
Affected Software
1 affected component
Jenkins Openid Connect Authentication Jenkins<2.5
Event History
Jan 24, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-24424?
CVE-2023-24424 is classified as a medium severity vulnerability.
2
How do I fix CVE-2023-24424?
To fix CVE-2023-24424, update the Jenkins OpenId Connect Authentication Plugin to version 2.5 or later.
3
What does CVE-2023-24424 affect?
CVE-2023-24424 affects versions 2.4 and earlier of the Jenkins OpenId Connect Authentication Plugin.
4
What is the issue described in CVE-2023-24424?
CVE-2023-24424 involves the plugin not invalidating the previous session upon user login, which can lead to security risks.
5
Who is impacted by CVE-2023-24424?
Any Jenkins user utilizing the OpenId Connect Authentication Plugin 2.4 or earlier is impacted by CVE-2023-24424.