PT-2023-19587 · Jenkins · Jenkins Bitbucket Oauth Plugin+1

·

CVE-2023-24427

·

Publicado

2023-01-24

·

Atualizado

2023-02-04

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Bitbucket OAuth Plugin versions 0.12 and earlier
Description The issue arises because the Jenkins Bitbucket OAuth Plugin does not invalidate the previous session on login, which can lead to potential security risks.
Recommendations For Jenkins Bitbucket OAuth Plugin versions 0.12 and earlier, update to a version that fixes this issue to ensure the previous session is properly invalidated on login. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-24427
GHSA-X9Q4-QWFH-9GJQ

Produtos afetados

Jenkins
Jenkins Bitbucket Oauth Plugin