Showing 11 vulnerabilities on this page for Jenkins Active Directory Plugin

Signals CISA KEV Ransomware Nuclei
Jenkins project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:Jenkins Active Directory Plugin LDAP Injection Vulnerability

Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries and to authenticate as a matching user whose password they know without knowing their exact user name.

CWE-90Jun 24, 2026
CVSS3.7v3.1EPSS0.224%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Jenkins Active Directory Plugin deserializes data from LDAP referrals without validation

Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.

CWE-502May 27, 2026
CVSS6.6v3.1EPSS0.26%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Jenkins Active Directory Plugin follows LDAP referrals by default

Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.

CWE-918May 27, 2026
CVSS6.6v3.1EPSS0.223%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Jenkins Active Directory Plugin vulnerable to Active Directory credential disclosure

Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active Directory credentials.

CWE-311Jul 12, 2023
CVSS5.9v3.1EPSS0.459%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

User passwords transmitted in plain text by Jenkins Active Directory Plugin

Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most configurations.

CWE-319Jan 12, 2022
CVSS6.5v3.1EPSS0.449%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

CSRF vulnerability in Jenkins Active Directory Plugin

A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials.

CWE-352Nov 4, 2020
CVSS4.3v3.1EPSS0.679%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Missing permission check in Jenkins Active Directory Plugin allows accessing domain health check page

A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page.

CWE-862Nov 4, 2020
CVSS4.3v3.1EPSS0.677%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Authentication cache in Active Directory Jenkins Plugin allows logging in with any password

Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is still in the optional cache when using Windows/ADSI mode.

CWE-287Nov 4, 2020
CVSS9.8v3.1EPSS1.7%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Authentication in Jenkins Active Directory Plugin

Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.

CWE-287Nov 4, 2020
CVSS9.8v3.1EPSS1.34%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Authentication (empty password) in Jenkins Active Directory Plugin

Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configuration of the Active Directory server.

CWE-287Nov 4, 2020
CVSS9.8v3.1EPSS1.67%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Jenkins Active Directory Plugin Improper certificate validation with StartTLS

An improper certificate validation vulnerability exists in Jenkins Active Directory Plugin 2.10 and earlier in src/main/java/hudson/plugins/active_directory/ActiveDirectoryDomain.java, src/main/java/hudson/plugins/active_directory/ActiveDirectorySecurityRealm.java, src/main/java/hudson/plugins/active_directory/ActiveDirectoryUnixAuthenticationProvider.java that allows attackers to impersonate the Active Directory server Jenkins connects to for authentication if Jenkins is configured to use Start

CWE-295Feb 6, 2019
CVSS7.4v3.0EPSS0.778%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX