Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Keycloak Authentication Plugin 2.3.0 and earlier allows attackers to trick users into logging in to the attacker's account.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0436 | A cross-site request forgery (CSRF) vulnerability in Jenkins Keycloak Authentication Plugin 2.3.0 and earlier allows attackers to trick users into logging in to the attacker's account. |
Github GHSA |
GHSA-9wrr-4r9v-26xc | CSRF vulnerability in Jenkins Keycloak Authentication Plugin |
References
History
Wed, 02 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-04-02T13:38:38.774Z
Reserved: 2023-01-23T00:00:00.000Z
Link: CVE-2023-24457
Updated: 2024-08-02T10:56:04.162Z
Status : Modified
Published: 2023-01-26T21:18:19.037
Modified: 2025-04-02T14:15:42.560
Link: CVE-2023-24457
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA