Active Directory Plugin for Jenkins Exposes Users to Man-in-the-Middle Attacks
CVE-2017-2649
8.1HIGH
Summary
The Active Directory Plugin for Jenkins versions up to 2.2 contains an important security flaw where it fails to properly verify the certificates of the Active Directory server. This negligence permits potential Man-in-the-Middle attacks, allowing an attacker to intercept and manipulate communications between Jenkins and the Active Directory server without detection. Users should take immediate action to secure their systems against this vulnerability.
Affected Version(s)
Active Directory Jenkins plugin <= 2.2
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved