Active Directory Plugin for Jenkins Exposes Users to Man-in-the-Middle Attacks
CVE-2017-2649

8.1HIGH

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
27 July 2018

Summary

The Active Directory Plugin for Jenkins versions up to 2.2 contains an important security flaw where it fails to properly verify the certificates of the Active Directory server. This negligence permits potential Man-in-the-Middle attacks, allowing an attacker to intercept and manipulate communications between Jenkins and the Active Directory server without detection. Users should take immediate action to secure their systems against this vulnerability.

Affected Version(s)

Active Directory Jenkins plugin <= 2.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.