Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.
References
Link | Resource |
---|---|
https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3001%20(1) | Vendor Advisory |
https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3001%20(1) | Vendor Advisory |
Configurations
History
21 Nov 2024, 08:04
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3001%20(1) - Vendor Advisory |
Information
Published : 2023-05-16 17:15
Updated : 2024-11-21 08:04
NVD link : CVE-2023-32993
Mitre link : CVE-2023-32993
CVE.ORG link : CVE-2023-32993
JSON object : View
Products Affected
jenkins
- saml_single_sign_on
CWE
CWE-345
Insufficient Verification of Data Authenticity