cbcvebase.
CVE-2023-37945
published 2023-07-12

CVE-2023-37945: A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attackers with Overall/Read permission to…

PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.45%
36.2th percentile
A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attackers with Overall/Read permission to download a string representation of the current security realm.

Affected

17 ranges
VendorProductVersion rangeFixed in
jenkinsactive_directory_plugin
jenkinsassembla_auth_plugin
jenkinsbenchmark_evaluator_plugin
jenkinsdatadog_plugin
jenkinselasticbox_ci_plugin
jenkinsexternal_monitor_job_type_plugin
jenkinsfor_more_information_see_the_plugin
jenkinsmacstadium_plugin
jenkinsmathworks_polyspace_plugin
jenkinsopenshift_login_plugin
jenkinsoracle_cloud_infrastructure_compute_plugin
jenkinsorka_by_macstadium_plugin
jenkinsrebuilder_plugin
jenkinssaml_single_sign_on>= 2.1.0 < 2.3.12.3.1
jenkinssumologic_publisher_plugin
jenkinstest_results_aggregator_plugin
jenkins_projectjenkins_saml_single_sign_on_plugin2.1.0 – 2.3.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.