CVE-2017-2649

Source
https://cve.org/CVERecord?id=CVE-2017-2649
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-2649.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-2649
Aliases
Published
2018-07-27T20:29:00.453Z
Modified
2026-03-15T13:59:54.786178Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.

References

Affected packages

Git / github.com/jenkinsci/active-directory-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/active-directory-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.2"
        }
    ]
}

Affected versions

active-directory-1.*
active-directory-1.19
active-directory-1.20
active-directory-1.21
active-directory-1.22
active-directory-1.23
active-directory-1.24
active-directory-1.25
active-directory-1.26
active-directory-1.27
active-directory-1.28
active-directory-1.29
active-directory-1.30
active-directory-1.31
active-directory-1.32
active-directory-1.33
active-directory-1.34
active-directory-1.35
active-directory-1.36
active-directory-1.37
active-directory-1.38
active-directory-1.39
active-directory-1.40
active-directory-1.41
active-directory-1.42
active-directory-1.43
active-directory-1.44
active-directory-1.45
active-directory-1.46
active-directory-1.47
active-directory-1.48
active-directory-1.49
active-directory-2.*
active-directory-2.0
active-directory-2.1
active-directory-2.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-2649.json"