Lucene search

K
cve[email protected]CVE-2023-33005
HistoryMay 16, 2023 - 5:15 p.m.

CVE-2023-33005

2023-05-1617:15:12
CWE-613
web.nvd.nist.gov
17
cve-2023-33005
jenkins
wso2
oauth plugin
session issue
nvd

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

0.0005 Low

EPSS

Percentile

18.3%

Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.

Affected configurations

NVD
Node
jenkinswso2_oauthRange1.0jenkins

CNA Affected

[
  {
    "defaultStatus": "unknown",
    "product": "Jenkins WSO2 Oauth Plugin",
    "vendor": "Jenkins Project",
    "versions": [
      {
        "lessThanOrEqual": "1.0",
        "status": "affected",
        "version": "0",
        "versionType": "maven"
      }
    ]
  }
]

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

0.0005 Low

EPSS

Percentile

18.3%

Related for CVE-2023-33005