CVE-2023-32993
Last modified
CVE-2023-32993 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Saml Single Sign On | <= 2.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-32993?
How severe is CVE-2023-32993?
How do I fix CVE-2023-32993?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-32988A missing permission check in Jenkins Azure VM Agents Plugin…4.3
- CVE-2023-32989A cross-site request forgery (CSRF) vulnerability in Jenkins…8.8
- CVE-2023-3299HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 AC…2.7
- CVE-2023-32990A missing permission check in Jenkins Azure VM Agents Plugin…6.5
- CVE-2023-32991A cross-site request forgery (CSRF) vulnerability in Jenkins…8.8
- CVE-2023-32992Missing permission checks in Jenkins SAML Single Sign On(SSO…8.8
- CVE-2023-32994Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier un…3.7
- CVE-2023-32995A cross-site request forgery (CSRF) vulnerability in Jenkins…8.8
- CVE-2023-32996A missing permission check in Jenkins SAML Single Sign On(SS…4.3
- CVE-2023-32997Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the…8.8
- CVE-2023-32998A cross-site request forgery (CSRF) vulnerability in Jenkins…8.8
- CVE-2023-32999A missing permission check in Jenkins AppSpider Plugin 1.0.1…4.3
Are you affected by CVE-2023-32993?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
