Description
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
Remediation
References
http://www.securityfocus.com/bid/96986
https://jenkins.io/security/advisory/2017-03-20/
Related Vulnerabilities
CVE-2016-10735 Vulnerability in maven package fr.norad.bootstrap:bootstrap
CVE-2020-4051 Vulnerability in npm package dijit
CVE-2022-1291 Vulnerability in maven package org.webjars.npm:tableexport.jquery.plugin
CVE-2016-10568 Vulnerability in npm package geoip-lite-country
CVE-2016-10557 Vulnerability in npm package appium-chromedriver