Skip to main content

Vendor/product archive

jenkins / saml_single_sign_on CVEs

Beta · best-effort

6 CVEs tagged to jenkins / saml_single_sign_on0 Critical, 3 High, 2 Medium, 1 Low, 0 Unrated.

CVE-2023-37945

Published Jul 12, 2023

A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attackers with Overall/Read permission to download a string repre…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32995

Published May 16, 2023

A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers to send an HTTP POST request with JSON body contain…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32994

Published May 16, 2023

Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve S…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-32993

Published May 16, 2023

Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32992

Published May 16, 2023

Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specifie…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32991

Published May 16, 2023

A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows attackers to send an HTTP request to an attacker-specified UR…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1