Jenkins / Active Directory
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-57288 | Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentica… | LOW | 3.7 | Jun 24, 2026 |
| CVE-2026-48919 | Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. | MEDIUM | 6.6 | May 27, 2026 |
| CVE-2026-48918 | Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default. | MEDIUM | 6.6 | May 27, 2026 |
| CVE-2023-37943 | Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory u… | MEDIUM | 5.9 | Jul 12, 2023 |
| CVE-2022-23105 | Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most… | MEDIUM | 6.5 | Jan 12, 2022 |
| CVE-2020-2303 | A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting… | MEDIUM | 4.3 | Nov 4, 2020 |
| CVE-2020-2302 | A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check… | MEDIUM | 4.3 | Nov 4, 2020 |
| CVE-2020-2301 | Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is sti… | CRITICAL | 9.8 | Nov 4, 2020 |
| CVE-2020-2300 | Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenki… | CRITICAL | 9.8 | Nov 4, 2020 |
| CVE-2020-2299 | Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password. | CRITICAL | 9.8 | Nov 4, 2020 |
| CVE-2019-1003009 | An improper certificate validation vulnerability exists in Jenkins Active Directory Plugin 2.10 and earlier in src/main/java/hudson/plugins/active_directory/Ac… | HIGH | 7.4 | Feb 6, 2019 |
| CVE-2017-2649 | It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby e… | HIGH | 8.1 | Jul 27, 2018 |
Showing 1 to 12 of 12 CVEs