Active Directory Plugin for Jenkins Exposes Users to Man-in-the-Middle Attacks
CVE-2017-2649
8.1HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 27 July 2018
What is CVE-2017-2649?
The Active Directory Plugin for Jenkins versions up to 2.2 contains an important security flaw where it fails to properly verify the certificates of the Active Directory server. This negligence permits potential Man-in-the-Middle attacks, allowing an attacker to intercept and manipulate communications between Jenkins and the Active Directory server without detection. Users should take immediate action to secure their systems against this vulnerability.
Affected Version(s)
Active Directory Jenkins plugin <= 2.2