PT-2023-3795 · Jenkins · Jenkins Saml Single Sign On(Sso) Plugin+1

Yaroslav Afenkin

·

Publicado

2023-05-16

·

Atualizado

2023-05-30

·

CVE-2023-32994

CVSS v3.1

3.7

Baixa

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins SAML Single Sign On(SSO) Plugin versions 2.1.0 and earlier
Description The issue is related to the lack of SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata. This could be exploited using a man-in-the-middle attack to intercept these connections, potentially allowing a remote attacker to disclose protected information.
Recommendations For Jenkins SAML Single Sign On(SSO) Plugin versions 2.1.0 and earlier, update to version 2.2.0 or later, which performs SSL/TLS certificate validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata. As a temporary workaround, consider restricting access to the plugin until the update is applied.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04086
CVE-2023-32994
GHSA-9M92-QWPC-QM78

Produtos afetados

Jenkins
Jenkins Saml Single Sign On(Sso) Plugin