CVE-2023-24427

CWE-3845 documents5 sources
Severity
9.8CRITICAL
EPSS
1.1%
top 22.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 26

Description

Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Session fixation vulnerability in Jenkins Bitbucket OAuth Plugin2023-01-26
OSV
Session fixation vulnerability in Jenkins Bitbucket OAuth Plugin2023-01-26
CVEList
CVE-2023-24427: Jenkins Bitbucket OAuth Plugin 02023-01-24

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2023-01-242023-01-24
CVE-2023-24427 (CRITICAL CVSS 9.8) | Jenkins Bitbucket OAuth Plugin 0.12 | cvebase.io