Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.
2023-05-16T17:15:11.937
2025-01-23T16:15:30.327
Modified
CVSSv3.1: 3.7 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jenkins | saml_single_sign_on | ≤ 2.1.0 | Yes |