Jenkins active directory plugin
This hub aggregates every CVE we track for Jenkins active directory plugin, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
11
CVEs tracked
3
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM6CRITICAL3LOW1HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
1
0
0
0
2024-102026-09
Latest CVEs
The 11 most recently published vulnerabilities affecting Jenkins active directory plugin.
- CVE-2026-57288Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated at...3.7
- CVE-2026-48919Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.6.6
- CVE-2026-48918Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.6.6
- CVE-2023-37943Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to...5.9
- CVE-2022-23105Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most configurations.6.5
- CVE-2020-2303A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously co...4.3
- CVE-2020-2301Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is still in the optional cache when using Wi...9.8
- CVE-2020-2302A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page.4.3
- CVE-2020-2299Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.9.8
- CVE-2020-2300Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the config...9.8
- CVE-2019-1003009An improper certificate validation vulnerability exists in Jenkins Active Directory Plugin 2.10 and earlier in src/main/java/hudson/plugins/active_directory/ActiveDirectoryDomain.java, src/main/jav...7.4
Product normalization is registry-driven with AI assist and human review. How it works