A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NJenkins Openid
APPJenkinsall versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
CI/CD
CWE
Related vulnerabilities
CVE-2023-24444CRITICAL9.8PL ✓same product
Jenkins OpenID Plugin: brak unieważnienia sesji przy logowaniu
CVE-2023-24446HIGH8.8same product
A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to...
CVE-2023-50770MEDIUM6.7same product
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as...
CVE-2023-24445MEDIUM6.1same product
Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately po...
CVE-2019-1003099MEDIUM6.5same product
A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate fo...