First published: Mon Mar 20 2017(Updated: )
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Active Directory | <=2.2 | |
maven/org.jenkins-ci.plugins:active-directory | <=2.2 | 2.3 |
<=2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2649 is a vulnerability found in the Active Directory Plugin for Jenkins up to and including version 2.2.
CVE-2017-2649 allows for Man-in-the-Middle attacks by not verifying certificates of the Active Directory server in Jenkins.
CVE-2017-2649 has a severity level of 8.1 (high).
You can find more information about CVE-2017-2649 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/96986) and [Jenkins Security Advisory](https://jenkins.io/security/advisory/2017-03-20/).
To fix CVE-2017-2649, it is recommended to update the Active Directory Plugin for Jenkins to version 2.3 or later.