ZeroHour

CVE-2023-37943

CVSS 3.1
5.9 medium
EPSS
<1%p38
Published
()
Modified
Description

Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active Directory credentials.

Vendors
jenkins
Products
active directory
Weakness
CWE-311
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.