CVE-2023-24428

MEDIUM5.7EPSS 0.09%

Cross-site request forgery vulnerability in Jenkins Bitbucket OAuth Plugin

Published: 1/26/2023Modified: 11/8/2023
Also known as:GHSA-685j-36qx-3vp2

Description

A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.7CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

References (4)