PT-2023-19587 · Jenkins · Jenkins Bitbucket Oauth Plugin+1

Kevin Guerroudj

·

Published

2023-01-24

·

Updated

2023-02-04

·

CVE-2023-24427

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Bitbucket OAuth Plugin versions 0.12 and earlier
Description The issue arises because the Jenkins Bitbucket OAuth Plugin does not invalidate the previous session on login, which can lead to potential security risks.
Recommendations For Jenkins Bitbucket OAuth Plugin versions 0.12 and earlier, update to a version that fixes this issue to ensure the previous session is properly invalidated on login. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2023-24427
GHSA-X9Q4-QWFH-9GJQ

Affected Products

Jenkins
Jenkins Bitbucket Oauth Plugin