CVE-2023-24447: CSRF
Published Jan 24, 2023
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers to connect to an attacker-specified AMQP(S) URL using attacker-specified username and password.
Affected Software
1 affected component
Jenkins Rabbitmq Consumer Jenkins<=2.8
Event History
Jan 24, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-24447?
CVE-2023-24447 is classified as a High severity vulnerability due to its potential to exploit cross-site request forgery in Jenkins.
2
How do I fix CVE-2023-24447?
To fix CVE-2023-24447, upgrade the RabbitMQ Consumer Plugin to version 2.9 or later.
3
What software is affected by CVE-2023-24447?
CVE-2023-24447 affects the Jenkins RabbitMQ Consumer Plugin versions 2.8 and earlier.
4
What type of vulnerability is CVE-2023-24447?
CVE-2023-24447 is a cross-site request forgery (CSRF) vulnerability.
5
What can an attacker do with CVE-2023-24447?
An attacker exploiting CVE-2023-24447 can connect to an attacker-specified AMQP(S) URL using chosen credentials.