CVE-2017-2649
published 2018-07-27CVE-2017-2649: It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby…
PriorityP336high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
0.96%
57.4th percentile
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | active_directory | <= 2.2 | — |
| jenkins | all_versions_no_fix_for_this_plugin | — | — |
| jenkins | classpath_step_plugin | — | — |
| jenkins | distfork_plugin | — | — |
| jenkins | distributed_fork_plugin | — | — |
| jenkins | email_extension_plugin | — | — |
| jenkins | jenkins_by_mailer_plugin | — | — |
| jenkins | pipeline_libraries_feature_no_fix_for_this_plugin | — | — |
| jenkins | ssh_build_agents_plugin | — | — |
| jenkins_project | active_directory_jenkins_plugin | <= 2.2 | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Jenkins Active Directory Plugin did not verify certificate of AD server
osv·2022-05-13
CVE-2017-2649 [HIGH] Jenkins Active Directory Plugin did not verify certificate of AD server
Jenkins Active Directory Plugin did not verify certificate of AD server
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
GHSA
Jenkins Active Directory Plugin did not verify certificate of AD server
ghsa·2022-05-13
CVE-2017-2649 [HIGH] CWE-295 Jenkins Active Directory Plugin did not verify certificate of AD server
Jenkins Active Directory Plugin did not verify certificate of AD server
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
Jenkins
Jenkins Security Advisory 2017-03-20
vendor_jenkins·2017-03-20·CVSS 6.8
CVE-2017-2648 [MEDIUM] Jenkins Security Advisory 2017-03-20
Title: Jenkins Security Advisory 2017-03-20
Jenkins Security Advisory 2017-03-20
This advisory announces vulnerabilities in these Jenkins plugins:
Active Directory
DistFork
Email Extension (Email-ext)
Mailer
Pipeline: Classpath Step
SSH Build Agents
Description
SSH Build Agents Plugin did not verify host keys
SECURITY-161 / CVE-2017-2648
The SSH Build Agents Plugin did not perform host key verification, thereby enabling Man-in-the-Middle attacks.
Active Directory Plugin did not verify certificate of AD server
SECURITY-251 / CVE-2017-2649
The Active Directory Plugin did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
Pipeline: Classpath Step plugin allowed Script Sec
No detection rules found.
No public exploits indexed.
2018-07-27
Published