ZeroHour

CVE-2017-2649

CVSS 3.0
8.1 high
EPSS
<1%p59
Published
()
Modified
Description

It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.

Vendors
jenkins
Products
active directory
Weakness
CWE-295
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.