CVE-2023-37945: Jenkins SAML Single Sign On

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attackers with Overall/Read permission to download a string representation of the current security realm.

Affected products

  • Jenkins SAML Single Sign On: from 2.1.0, before 2.3.1 (fixed in 2.3.1)

Published 2023-07-12. Last modified 2026-06-17.