Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-32993


Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.


Published

2023-05-16T17:15:11.893

Last Modified

2025-01-23T20:15:30.720

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-345
  • Type: Secondary
    CWE-346

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins saml_single_sign_on ≤ 2.0.2 Yes

References