Description
Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is still in the optional cache when using Windows/ADSI mode.
Remediation
References
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-2123
Related Vulnerabilities
CVE-2023-29523 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2021-3690 Vulnerability in maven package io.undertow:undertow-core
CVE-2023-48240 Vulnerability in maven package org.xwiki.platform:xwiki-platform-diff-xml
CVE-2020-13951 Vulnerability in maven package org.apache.openmeetings:openmeetings-server
CVE-2018-1000129 Vulnerability in maven package org.jolokia:jolokia-core