CVE-2023-24457

MEDIUM6.5EPSS 0.09%

CSRF vulnerability in Jenkins Keycloak Authentication Plugin

Published: 1/26/2023Modified: 2/16/2024

Description

A cross-site request forgery (CSRF) vulnerability in Jenkins Keycloak Authentication Plugin 2.3.0 and earlier allows attackers to trick users into logging in to the attacker's account.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

References (3)