Description
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
Remediation
References
http://www.securityfocus.com/bid/96986
https://jenkins.io/security/advisory/2017-03-20/
Related Vulnerabilities
CVE-2020-26301 Vulnerability in npm package ssh2
CVE-2020-28480 Vulnerability in maven package org.webjars.bower:jointjs
CVE-2023-42399 Vulnerability in npm package jodit
CVE-2019-10313 Vulnerability in maven package org.jenkins-ci.plugins:twitter
CVE-2014-3630 Vulnerability in maven package com.typesafe.play:play_2.11