Improper Certificate Validation in SAML Single Sign On(SSO) - CVE-2023-32994
Published: May 17, 2023
SAML Single Sign On(SSO)
Jenkins
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected plugin unconditionally disables SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata.. A remote attacker can perform a man-in-the-middle (MitM) attack and intercept these connections.