Description
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
Remediation
References
http://www.securityfocus.com/bid/96986
https://jenkins.io/security/advisory/2017-03-20/
Related Vulnerabilities
CVE-2018-3734 Vulnerability in npm package stattic
CVE-2012-0392 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2016-4970 Vulnerability in maven package io.netty:netty-handler
CVE-2020-28452 Vulnerability in maven package com.softwaremill.akka-http-session:core_2.13
CVE-2020-28500 Vulnerability in maven package org.fujion.webjars:lodash