CVE-2019-1003009: High severity jenkins active directory vulnerability
An improper certificate validation vulnerability exists in Jenkins Active Directory Plugin 2.10 and earlier in src/main/java/hudson/plugins/activedirectory/ActiveDirectoryDomain.java, src/main/java/hudson/plugins/activedirectory/ActiveDirectorySecurityRealm.java, src/main/java/hudson/plugins/activedirectory/ActiveDirectoryUnixAuthenticationProvider.java that allows attackers to impersonate the Active Directory server Jenkins connects to for authentication if Jenkins is configured to use StartTLS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1003009?
The severity of CVE-2019-1003009 is high with a score of 7.4.
Which software versions are affected by CVE-2019-1003009?
Jenkins Active Directory Plugin versions up to and including 2.10 are affected by CVE-2019-1003009.
What is the CWE category associated with CVE-2019-1003009?
CVE-2019-1003009 is associated with CWE category 295.
How can I fix CVE-2019-1003009?
To fix CVE-2019-1003009, users should update to a version of Jenkins Active Directory Plugin that is higher than 2.10.
Where can I find more information about CVE-2019-1003009?
You can find more information about CVE-2019-1003009 at the following URL: https://jenkins.io/security/advisory/2019-01-28/#SECURITY-859