CVE-2023-32993

Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:saml_single_sign_on:*:*:*:*:*:jenkins:*:*

History

23 Jan 2025, 20:15

Type Values Removed Values Added
CWE CWE-346

21 Nov 2024, 08:04

Type Values Removed Values Added
References () https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3001%20(1) - Vendor Advisory () https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3001%20(1) - Vendor Advisory

26 May 2023, 02:02

Type Values Removed Values Added
CPE cpe:2.3:a:jenkins:saml_single_sign_on:*:*:*:*:*:jenkins:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CWE CWE-345
References (MISC) https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3001%20(1) - (MISC) https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3001%20(1) - Vendor Advisory

16 May 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-16 17:15

Updated : 2025-01-23 20:15


NVD link : CVE-2023-32993

Mitre link : CVE-2023-32993

CVE.ORG link : CVE-2023-32993


JSON object : View

Products Affected

jenkins

  • saml_single_sign_on
CWE
CWE-345

Insufficient Verification of Data Authenticity

CWE-346

Origin Validation Error