Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jenkins

Published: 2023-05-16T16:00:12.489Z

Updated: 2023-10-24T12:50:15.800Z

Reserved: 2023-05-16T10:55:43.519Z


Link: CVE-2023-32993

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-05-16T17:15:11.893

Modified: 2023-05-26T02:02:43.460


Link: CVE-2023-32993

JSON object: View

cve-icon Redhat Information

No data.

CWE