Логотип exploitDog
bind:CVE-2023-32993
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-32993

Количество 2

Количество 2

nvd логотип

CVE-2023-32993

больше 2 лет назад

Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-6v6h-rw43-97fh

больше 2 лет назад

Jenkins SAML Single Sign On(SSO) Plugin missing hostname validation

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-32993

Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-6v6h-rw43-97fh

Jenkins SAML Single Sign On(SSO) Plugin missing hostname validation

CVSS3: 4.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу