GHSA-vcgj-j8c5-2h52
GitHub Security Advisory
Jenkins Active Directory Plugin did not verify certificate of AD server
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
Affected Packages
Maven
org.jenkins-ci.plugins:active-directory
Affected versions:
0
(fixed in 2.3)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.