[MAVEN:GHSA-6V6H-RW43-97FH] Jenkins SAML Single Sign On(SSO) Plugin missing hostname validation

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata.

This lack of validation could be abused using a man-in-the-middle attack to intercept these connections.

SAML Single Sign On(SSO) Plugin 2.1.0 performs hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata.

Package Affected Version
pkg:maven/io.jenkins.plugins/miniorange-saml-sp < 2.1.0
ID
MAVEN:GHSA-6V6H-RW43-97FH
Severity
moderate
URL
https://github.com/advisories/GHSA-6v6h-rw43-97fh
Published
2023-05-16T18:30:16
(16 months ago)
Modified
2023-11-08T05:05:43
(10 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.jenkins.plugins/miniorange-saml-sp io.jenkins.plugins miniorange-saml-sp < 2.1.0
Fixed pkg:maven/io.jenkins.plugins/miniorange-saml-sp io.jenkins.plugins miniorange-saml-sp = 2.1.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...