CVE-2023-24440: Medium severity jenkins vulnerability
Published Jan 24, 2023
·Updated
Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
Affected Software
1 affected component
Jenkins Jira Pipeline Steps Jenkins<=2.0.165.v8846cf59f3db
Event History
Jan 24, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-24440?
The severity of CVE-2023-24440 is considered important due to the potential exposure of private keys.
2
How do I fix CVE-2023-24440?
To fix CVE-2023-24440, upgrade the Jenkins JIRA Pipeline Steps Plugin to version 2.0.166 or later.
3
What vulnerabilities does CVE-2023-24440 introduce?
CVE-2023-24440 introduces a risk of exposing private keys due to their transmission in plain text.
4
Which versions of the Jenkins JIRA Pipeline Steps Plugin are affected by CVE-2023-24440?
CVE-2023-24440 affects Jenkins JIRA Pipeline Steps Plugin versions 2.0.165.v8846cf59f3db and earlier.
5
Is there a known mitigation for CVE-2023-24440?
The mitigation for CVE-2023-24440 is to update to the latest version of the Jenkins JIRA Pipeline Steps Plugin.