Количество 2
Количество 2
CVE-2023-32993
Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.
GHSA-6v6h-rw43-97fh
Jenkins SAML Single Sign On(SSO) Plugin missing hostname validation
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-32993 Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections. | CVSS3: 4.8 | 0% Низкий | больше 2 лет назад | |
GHSA-6v6h-rw43-97fh Jenkins SAML Single Sign On(SSO) Plugin missing hostname validation | CVSS3: 4.8 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу