Description
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
Remediation
References
https://jenkins.io/security/advisory/2017-03-20/
http://www.securityfocus.com/bid/96986
Related Vulnerabilities
CVE-2023-49653 Vulnerability in maven package org.jenkins-ci.plugins:jira
CVE-2023-47327 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2021-25913 Vulnerability in npm package set-or-get
CVE-2017-4973 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-uaa