CVE-2023-37943

Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active Directory credentials.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:active_directory:*:*:*:*:*:jenkins:*:*

History

No history.

Information

Published : 2023-07-12 16:15

Updated : 2023-07-20 01:46


NVD link : CVE-2023-37943

Mitre link : CVE-2023-37943

CVE.ORG link : CVE-2023-37943


JSON object : View

Products Affected

jenkins

  • active_directory
CWE
CWE-311

Missing Encryption of Sensitive Data