CVE-2023-50771: Medium severity jenkins openid vulnerability
Published Dec 13, 2023
·Updated
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
Affected Software
3 affected componentsFixes available
maven/org.jenkins-ci.plugins:oic-auth<3.0
3.0
jenkins Openid Jenkins<=2.6
jenkins Openid Connect Authentication Jenkins<=2.6
Event History
Dec 13, 2023
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
Description
Advisory Published
06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-50771?
CVE-2023-50771 is classified as a medium severity vulnerability.
2
How do I fix CVE-2023-50771?
To fix CVE-2023-50771, upgrade the Jenkins OpenId Connect Authentication Plugin to version 3.0 or later.
3
What are the implications of CVE-2023-50771?
CVE-2023-50771 allows attackers to perform phishing attacks by improperly determining redirect URLs after login.
4
Which versions of Jenkins are affected by CVE-2023-50771?
Jenkins OpenId Connect Authentication Plugin versions 2.6 and earlier are affected by CVE-2023-50771.
5
What type of attack is associated with CVE-2023-50771?
CVE-2023-50771 is associated with phishing attacks due to improper validation of redirect URLs.