CVE-2023-24446

HIGH8.8EPSS 0.12%

Cross-site request forgery vulnerability in Jenkins OpenID Plugin

Published: 1/26/2023Modified: 11/8/2023

Description

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to trick users into logging in to the attacker's account.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References (2)