First published: Tue Jan 24 2023(Updated: )
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.
Credit: jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Bitbucket OAuth | <0.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-24428 is classified as medium due to its potential to allow unauthorized actions via cross-site request forgery (CSRF).
To fix CVE-2023-24428, upgrade Jenkins Bitbucket OAuth Plugin to version 0.13 or later.
CVE-2023-24428 allows attackers to trick users into logging into the attacker's account through cross-site request forgery.
CVE-2023-24428 affects Jenkins Bitbucket OAuth Plugin versions 0.12 and earlier.
There is no known workaround for CVE-2023-24428 other than upgrading to a secure version of the plugin.