CVE-2023-24426: Jenkins Azure AD Plugin Session Invalidation Flaw
CVE-2023-24426 Published on January 26, 2023
Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login.
Vulnerability Analysis
CVE-2023-24426 is exploitable with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Products Associated with CVE-2023-24426
Want to know whenever a new CVE is published for Jenkins Azure Ad? stack.watch will email you.
Affected Versions
Jenkins Project Jenkins Azure AD Plugin:- Version unspecified, <= 303.va_91ef20ee49f is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.