3.7
CVSSv3

CVE-2023-32994

Published: 16/05/2023 Updated: 30/05/2023
CVSS v3 Base Score: 3.7 | Impact Score: 1.4 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and previous versions unconditionally disables SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins saml single sign on