CVE-2019-1003009

HIGH

Jenkins Active Directory Plugin <2.10 - RCE

Title source: llm
STIX 2.1

Description

An improper certificate validation vulnerability exists in Jenkins Active Directory Plugin 2.10 and earlier in src/main/java/hudson/plugins/active_directory/ActiveDirectoryDomain.java, src/main/java/hudson/plugins/active_directory/ActiveDirectorySecurityRealm.java, src/main/java/hudson/plugins/active_directory/ActiveDirectoryUnixAuthenticationProvider.java that allows attackers to impersonate the Active Directory server Jenkins connects to for authentication if Jenkins is configured to use StartTLS.

References (1)

Core 1
Core References

Scores

CVSS v3 7.4
EPSS 0.0003
EPSS Percentile 8.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-295
Status published
Products (2)
jenkins/active_directory < 2.10
org.jenkins-ci.plugins/active-directory 0 - 2.11Maven
Published Feb 06, 2019
Tracked Since Feb 18, 2026