cbcvebase.
CVE-2023-37943
published 2023-07-12

CVE-2023-37943: Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory…

PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.46%
36.8th percentile
Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active Directory credentials.

Affected

17 ranges
VendorProductVersion rangeFixed in
jenkinsactive_directory<= 2.30
jenkinsactive_directory_plugin
jenkinsassembla_auth_plugin
jenkinsbenchmark_evaluator_plugin
jenkinsdatadog_plugin
jenkinselasticbox_ci_plugin
jenkinsexternal_monitor_job_type_plugin
jenkinsfor_more_information_see_the_plugin
jenkinsmacstadium_plugin
jenkinsmathworks_polyspace_plugin
jenkinsopenshift_login_plugin
jenkinsoracle_cloud_infrastructure_compute_plugin
jenkinsorka_by_macstadium_plugin
jenkinsrebuilder_plugin
jenkinssumologic_publisher_plugin
jenkinstest_results_aggregator_plugin
jenkins_projectjenkins_active_directory_plugin<= 2.30
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.