CVE-2023-24456: Critical severity keycloak authenticator vulnerability
Published Jan 24, 2023
·Updated
Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins:keycloak<=2.3.0
2.3.1
Jenkins Keycloak Authentication Jenkins<=2.3.0
Event History
Jan 24, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Jan 26, 2023
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-24456?
CVE-2023-24456 is rated as a critical vulnerability due to the risk of unauthorized access and session hijacking.
2
How do I fix CVE-2023-24456?
To fix CVE-2023-24456, upgrade the Jenkins Keycloak Authentication Plugin to version 2.3.1 or later.
3
What is the impact of CVE-2023-24456?
The impact of CVE-2023-24456 is that it allows attackers to retain access to a user's previous session after they have logged in.
4
Which versions of Jenkins are affected by CVE-2023-24456?
CVE-2023-24456 affects Jenkins Keycloak Authentication Plugin versions 2.3.0 and earlier.
5
Is there a temporary workaround for CVE-2023-24456?
No official temporary workaround is available for CVE-2023-24456, the recommended solution is to update to the fixed version.