CVE-2023-24440: Medium severity jenkins vulnerability

Published Jan 24, 2023
·
Updated

Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

Affected Software

1 affected component
Jenkins Jira Pipeline Steps Jenkins<=2.0.165.v8846cf59f3db

Event History

Jan 24, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2023-24440?

The severity of CVE-2023-24440 is considered important due to the potential exposure of private keys.

2

How do I fix CVE-2023-24440?

To fix CVE-2023-24440, upgrade the Jenkins JIRA Pipeline Steps Plugin to version 2.0.166 or later.

3

What vulnerabilities does CVE-2023-24440 introduce?

CVE-2023-24440 introduces a risk of exposing private keys due to their transmission in plain text.

4

Which versions of the Jenkins JIRA Pipeline Steps Plugin are affected by CVE-2023-24440?

CVE-2023-24440 affects Jenkins JIRA Pipeline Steps Plugin versions 2.0.165.v8846cf59f3db and earlier.

5

Is there a known mitigation for CVE-2023-24440?

The mitigation for CVE-2023-24440 is to update to the latest version of the Jenkins JIRA Pipeline Steps Plugin.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203