cbcvebase.
CVE-2017-2649
published 2018-07-27

CVE-2017-2649: It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby…

PriorityP336high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
0.96%
57.4th percentile
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.

Affected

10 ranges
VendorProductVersion rangeFixed in
jenkinsactive_directory<= 2.2
jenkinsall_versions_no_fix_for_this_plugin
jenkinsclasspath_step_plugin
jenkinsdistfork_plugin
jenkinsdistributed_fork_plugin
jenkinsemail_extension_plugin
jenkinsjenkins_by_mailer_plugin
jenkinspipeline_libraries_feature_no_fix_for_this_plugin
jenkinsssh_build_agents_plugin
jenkins_projectactive_directory_jenkins_plugin<= 2.2

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.