« Volver al listado

Jenkins

Jenkins Active Directory: vulnerabilidades y CVE

Jenkins Active Directory tiene 12 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses3
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-57288Baja (3.7)0.33%—24 jun 2026
Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP…
CVE-2026-48919Media (6.6)0.43%—27 may 2026
Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.
CVE-2026-48918Media (6.6)0.37%—27 may 2026
Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.
CVE-2023-37943Media (5.9)0.46%—12 jul 2023
Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network…
CVE-2022-23105Media (6.5)0.45%—12 ene 2022
Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most configurations.
CVE-2020-2303Media (4.3)0.68%—4 nov 2020
A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active…
CVE-2020-2302Media (4.3)0.68%—4 nov 2020
A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page.
CVE-2020-2301Crítica (9.8)1.7%—4 nov 2020
Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is still in the optional cache when using Windows/ADSI mode.
CVE-2020-2300Crítica (9.8)1.7%—4 nov 2020
Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configuration of the Active…
CVE-2020-2299Crítica (9.8)1.3%—4 nov 2020
Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.
CVE-2019-1003009Alta (7.4)0.78%—6 feb 2019
An improper certificate validation vulnerability exists in Jenkins Active Directory Plugin 2.10 and earlier in src/main/java/hudson/plugins/active_directory/ActiveDirectoryDomain.java,…
CVE-2017-2649Alta (8.1)0.96%—27 jul 2018
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.

Otros productos de Jenkins