Description
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
Remediation
References
http://www.securityfocus.com/bid/96986
https://jenkins.io/security/advisory/2017-03-20/
Related Vulnerabilities
CVE-2019-0191 Vulnerability in maven package org.apache.karaf.kar:org.apache.karaf.kar.core
CVE-2019-16557 Vulnerability in maven package com.redgate.plugins.redgatesqlci:redgate-sql-ci
CVE-2019-18213 Vulnerability in maven package org.lsp4xml:org.eclipse.lsp4xml.extensions.emmet
CVE-2020-7744 Vulnerability in maven package com.mintegral.msdk:alphab
CVE-2021-21293 Vulnerability in maven package org.http4s:blaze-core_2.13