Vulnerability GHSA-2wf5-4mf7-vmh3
Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 years ago
May 24, 2022 at 05:33 PM UTC
CSRF vulnerability in Jenkins Active Directory Plugin
1.18.0 - 1.39.0 and 1.41.0 - 2.19.0
1.18.0 - 1.39.0 and 1.41.0 - 2.19.0
Summary
CSRF vulnerability in Jenkins Active Directory Plugin
Details
Jenkins Active Directory Plugin 2.19 and earlier does not require POST requests for multiple HTTP endpoints implementing connection and authentication tests, resulting in cross-site request forgery (CSRF) vulnerabilities.
This vulnerability allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials.
Active Directory Plugin 2.20 requires POST requests for the affected HTTP endpoints.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
3 months ago
Jenkins Active Directory Plugin has an LDAP injection vulnerability
1.18.0 - 1.39.0 and 1.41.0 - 2.20.0 and 2.22.0 - 2.41.1 GHSA-gx55-p8g7-p3fh
1.18.0 - 1.39.0 and 1.41.0 - 2.20.0 and 2.22.0 - 2.41.1 GHSA-gx55-p8g7-p3fh
Medium Risk
4 months ago
Jenkins Active Directory Plugin deserializes data from LDAP referrals without validation
1.18.0 - 1.39.0 and 1.41.0 - 2.20.0 and 2.22.0 - 2.41.0 GHSA-p2gw-f3rv-82mw
1.18.0 - 1.39.0 and 1.41.0 - 2.20.0 and 2.22.0 - 2.41.0 GHSA-p2gw-f3rv-82mw
Medium Risk
4 months ago
Jenkins Active Directory Plugin follows LDAP referrals by default
1.18.0 - 1.39.0 and 1.41.0 - 2.20.0 and 2.22.0 - 2.41.0 GHSA-wrhr-54p6-q97f
1.18.0 - 1.39.0 and 1.41.0 - 2.20.0 and 2.22.0 - 2.41.0 GHSA-wrhr-54p6-q97f
Medium Risk
3 years ago
Jenkins Active Directory Plugin vulnerable to Active Directory credential disclosure
1.18.0 - 1.39.0 and 1.41.0 - 2.20.0 and 2.22.0 - 2.30.0 GHSA-g8c3-6fj2-87w7
1.18.0 - 1.39.0 and 1.41.0 - 2.20.0 and 2.22.0 - 2.30.0 GHSA-g8c3-6fj2-87w7
Critical
4 years ago
Improper Authentication (empty password) in Jenkins Active Directory Plugin
1.18.0 - 1.39.0 and 1.41.0 - 2.19.0 GHSA-8wcw-cw2f-h4g2
1.18.0 - 1.39.0 and 1.41.0 - 2.19.0 GHSA-8wcw-cw2f-h4g2
Impacted packages
Timeline
Published
4 years ago
May 24, 2022 at 05:33 PM UTC
Last Modified
2 years ago
February 16, 2024 at 08:22 AM UTC