CVE-2023-24434: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24434?
CVE-2023-24434 is classified as a medium severity vulnerability due to its potential impact on account credentials.
How do I fix CVE-2023-24434?
To fix CVE-2023-24434, upgrade the Jenkins GitHub Pull Request Builder Plugin to version 1.42.3 or later.
What are the consequences of CVE-2023-24434?
Exploiting CVE-2023-24434 can allow attackers to gain unauthorized access to credentials stored in Jenkins.
Which versions of Jenkins are affected by CVE-2023-24434?
CVE-2023-24434 affects Jenkins GitHub Pull Request Builder Plugin versions up to and including 1.42.2.
Is CVE-2023-24434 a common vulnerability?
Yes, CVE-2023-24434 is a recognized cross-site request forgery (CSRF) vulnerability commonly found in web applications.