PT-2023-3795 · Jenkins · Jenkins Saml Single Sign On(Sso) Plugin+1

Yaroslav Afenkin

·

Published

2023-05-16

·

Updated

2023-05-30

·

CVE-2023-32994

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins SAML Single Sign On(SSO) Plugin versions 2.1.0 and earlier
Description The issue is related to the lack of SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata. This could be exploited using a man-in-the-middle attack to intercept these connections, potentially allowing a remote attacker to disclose protected information.
Recommendations For Jenkins SAML Single Sign On(SSO) Plugin versions 2.1.0 and earlier, update to version 2.2.0 or later, which performs SSL/TLS certificate validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata. As a temporary workaround, consider restricting access to the plugin until the update is applied.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04086
CVE-2023-32994
GHSA-9M92-QWPC-QM78

Affected Products

Jenkins
Jenkins Saml Single Sign On(Sso) Plugin