First published: Tue Jan 24 2023(Updated: )
Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login.
Credit: jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins OpenId Connect Authentication Plugin | <2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24424 is classified as a medium severity vulnerability.
To fix CVE-2023-24424, update the Jenkins OpenId Connect Authentication Plugin to version 2.5 or later.
CVE-2023-24424 affects versions 2.4 and earlier of the Jenkins OpenId Connect Authentication Plugin.
CVE-2023-24424 involves the plugin not invalidating the previous session upon user login, which can lead to security risks.
Any Jenkins user utilizing the OpenId Connect Authentication Plugin 2.4 or earlier is impacted by CVE-2023-24424.