CVE-2023-32994: Medium severity Jenkins Saml Single Sign On Jenkins vulnerability
Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.
Other sources
Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata.
This lack of validation could be abused using a man-in-the-middle attack to intercept these connections.
SAML Single Sign On(SSO) Plugin 2.2.0 performs SSL/TLS certificate validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/io.jenkins.plugins:miniorange-saml-spto a version that resolves this vulnerability.Fixed in 2.2.0 - Upgrade
Upgrade
Jenkins SAML Single Sign On(SSO) Pluginto a version that resolves this vulnerability.Fixed in 2.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32994?
CVE-2023-32994 has a critical severity level due to the potential for man-in-the-middle attacks.
How do I fix CVE-2023-32994?
To fix CVE-2023-32994, upgrade the Jenkins SAML Single Sign On Plugin to version 2.2.0 or later.
What systems are affected by CVE-2023-32994?
CVE-2023-32994 affects Jenkins SAML Single Sign On Plugin versions 2.1.0 and earlier.
What is impacted by CVE-2023-32994?
CVE-2023-32994 impacts the SSL/TLS certificate validation process for connections to miniOrange or configured IdPs.
Can CVE-2023-32994 be exploited?
Yes, CVE-2023-32994 can be exploited through a man-in-the-middle attack if SSL/TLS validation is disabled.