CVE-2023-24428: CSRF
Published Jan 24, 2023
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.
Affected Software
1 affected component
Jenkins Bitbucket Oauth Jenkins<0.13
Event History
Jan 24, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-24428?
The severity of CVE-2023-24428 is classified as medium due to its potential to allow unauthorized actions via cross-site request forgery (CSRF).
2
How do I fix CVE-2023-24428?
To fix CVE-2023-24428, upgrade Jenkins Bitbucket OAuth Plugin to version 0.13 or later.
3
What does CVE-2023-24428 allow an attacker to do?
CVE-2023-24428 allows attackers to trick users into logging into the attacker's account through cross-site request forgery.
4
Which versions of Jenkins Bitbucket OAuth are affected by CVE-2023-24428?
CVE-2023-24428 affects Jenkins Bitbucket OAuth Plugin versions 0.12 and earlier.
5
Is there a workaround for CVE-2023-24428 if I cannot upgrade?
There is no known workaround for CVE-2023-24428 other than upgrading to a secure version of the plugin.