CVE-2023-32994: Jenkins SAML Single Sign On

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.

Affected products

  • Jenkins SAML Single Sign On: up to and including 2.1.0

Published 2023-05-16. Last modified 2026-06-17.