Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1462 | Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML. |
Github GHSA |
GHSA-3xf9-pgc2-mr9c | Jenkins SAML Single Sign On(SSO) Plugin missing permission checks |
Thu, 23 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-01-23T20:06:44.604Z
Reserved: 2023-05-16T10:55:43.519Z
Link: CVE-2023-32992
Updated: 2024-08-02T15:32:46.552Z
Status : Modified
Published: 2023-05-16T17:15:11.850
Modified: 2025-01-23T20:15:30.513
Link: CVE-2023-32992
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA