CVE-2023-24445: Medium severity jenkins openid vulnerability
Published Jan 24, 2023
·Updated
Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins.
Affected Software
1 affected component
Jenkins Openid Jenkins<=2.4
Event History
Jan 24, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-24445?
CVE-2023-24445 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2023-24445?
To fix CVE-2023-24445, upgrade the Jenkins OpenID Plugin to version 2.5 or later.
3
What impact does CVE-2023-24445 have on users?
CVE-2023-24445 may allow attackers to redirect users to malicious sites after login.
4
Which versions of Jenkins are affected by CVE-2023-24445?
Jenkins OpenID Plugin versions 2.4 and earlier are affected by CVE-2023-24445.
5
Is there a workaround for CVE-2023-24445?
Currently, there are no known workarounds for CVE-2023-24445; upgrading is the recommended solution.