CVE-2023-24446: CSRF
Published Jan 24, 2023
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to trick users into logging in to the attacker's account.
Affected Software
1 affected component
Jenkins Openid Jenkins<=2.4
Event History
Jan 24, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-24446?
CVE-2023-24446 is considered a high severity cross-site request forgery (CSRF) vulnerability.
2
How do I fix CVE-2023-24446?
To mitigate CVE-2023-24446, upgrade to Jenkins OpenID Plugin version 2.5 or later.
3
What does CVE-2023-24446 allow an attacker to do?
CVE-2023-24446 allows attackers to trick users into logging into the attacker's account through CSRF.
4
Which versions of Jenkins OpenID are affected by CVE-2023-24446?
Jenkins OpenID Plugin versions 2.4 and earlier are affected by CVE-2023-24446.
5
What is the exploit type for CVE-2023-24446?
CVE-2023-24446 is classified as a cross-site request forgery (CSRF) vulnerability.