Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-37943


Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active Directory credentials.


Published

2023-07-12T16:15:13.063

Last Modified

2024-11-21T08:12:30.647

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-311

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins active_directory ≤ 2.30 Yes

References