CVE-2024-23902 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Jenkins GitLab Branch Source Plugin versions 684.vea_fa_7c1e2fe3 and earlier. This medium-severity vulnerability (CVSS 4.3) allows an attacker to trick a user into connecting to an attacker-specified URL, potentially leading to unauthorized actions. While the attack complexity is low, it requires user interaction and primarily impacts integrity with no confidentiality or availability impact. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 684.vea_fa_7c1e2fe3CPE matchmatch criteria | cpe:2.3:a:jenkins:github_branch_source:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.