GHSA-p4wr-9wfm-f9jw
Dashboard / Vulnerabilities / GHSA-p4wr-9wfm-f9jw
Summary: Jenkins SAML Single Sign On(SSO) Plugin missing permission check
Details: Jenkins SAML Single Sign On(SSO) Plugin 2.3.0 and earlier does not perform a permission check in an HTTP endpoint. This allows attackers with Overall/Read permission to download a string representation of the current security realm (Java `Object#toString()`), which potentially includes sensitive information. SAML Single Sign On(SSO) Plugin 2.3.1 requires Overall/Administer permission to access the affected HTTP endpoint, and only allows downloading a string representation if the current security realm is this plugin’s.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-37945, https://www.jenkins.io/security/advisory/2023-07-12/#SECURITY-3164, http://www.openwall.com/lists/oss-security/2023/07/12/2
Affected packages
Package
Name: io.jenkins.plugins:miniorange-saml-sp
Purl: pkg:maven/io.jenkins.plugins/miniorange-saml-sp
Affected ranges
Type: ECOSYSTEM
Events:
