alpine · CVE-2024-23902

Quick triage

Priority: not assigned Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2024-23902: 1 source package rows (jenkins); 35 state rows across 5 repos (3.19-community, 3.20-community, 3.22-community, 3.23-community, edge-community); fixed 0, open 35.

Description:

A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier allows attackers to connect to an attacker-specified URL.

cvelogic Threat Intelligence