Improper Redirect Vulnerability in Jenkins OpenID Plugin by Jenkins
CVE-2023-24445
6.1MEDIUM
Key Information:
- Vendor
Jenkins
- Status
- Vendor
- CVE Published:
- 26 January 2023
What is CVE-2023-24445?
The Jenkins OpenID Plugin versions up to 2.4 are vulnerable due to improper handling of redirect URLs following user login. This vulnerability can permit a malicious actor to redirect users to unintended locations, potentially leading to phishing attacks or unauthorized actions within the Jenkins environment. It is essential for users of affected versions to update to mitigate the risks posed by this security flaw.
Affected Version(s)
Jenkins OpenID Plugin <= 2.4