CVE-2022-23105

MEDIUM

Jenkins Active Directory Plugin < 2.25 - Cleartext Transmission of Sensitive Information

Title source: llm
STIX 2.1

Description

Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most configurations.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/01/12/6

Scores

CVSS v3 6.5
EPSS 0.0001
EPSS Percentile 1.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-319
Status published
Products (2)
jenkins/active_directory < 2.25
org.jenkins-ci.plugins/active-directory 0 - 2.25.1Maven
Published Jan 12, 2022
Tracked Since Feb 18, 2026