CVE-2023-24448: Medium severity rabbitmq vulnerability
Published Jan 24, 2023
·Updated
A missing permission check in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified AMQP(S) URL using attacker-specified username and password.
Affected Software
1 affected component
Jenkins Rabbitmq Consumer Jenkins<=2.8
Event History
Jan 24, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-24448?
CVE-2023-24448 is classified as a high-severity vulnerability.
2
How do I fix CVE-2023-24448?
To fix CVE-2023-24448, upgrade RabbitMQ Consumer Plugin to version 2.9 or later.
3
What products are affected by CVE-2023-24448?
CVE-2023-24448 affects Jenkins RabbitMQ Consumer Plugin versions 2.8 and earlier.
4
What are the implications of CVE-2023-24448?
CVE-2023-24448 allows attackers with Overall/Read permission to connect to arbitrary AMQP(S) servers using specified credentials.
5
Is there a workaround for CVE-2023-24448?
Currently, there is no specific workaround for CVE-2023-24448 other than updating the plugin.