CVE-2019-1003009

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-1003009
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-1003009.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-1003009
Aliases
Published
2019-02-06T16:29:00Z
Modified
2024-09-03T02:21:07.560215Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

An improper certificate validation vulnerability exists in Jenkins Active Directory Plugin 2.10 and earlier in src/main/java/hudson/plugins/activedirectory/ActiveDirectoryDomain.java, src/main/java/hudson/plugins/activedirectory/ActiveDirectorySecurityRealm.java, src/main/java/hudson/plugins/active_directory/ActiveDirectoryUnixAuthenticationProvider.java that allows attackers to impersonate the Active Directory server Jenkins connects to for authentication if Jenkins is configured to use StartTLS.

References

Affected packages

Git / github.com/jenkinsci/active-directory-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/active-directory-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

active-directory-1.*

active-directory-1.19
active-directory-1.20
active-directory-1.21
active-directory-1.22
active-directory-1.23
active-directory-1.24
active-directory-1.25
active-directory-1.26
active-directory-1.27
active-directory-1.28
active-directory-1.29
active-directory-1.30
active-directory-1.31
active-directory-1.32
active-directory-1.33
active-directory-1.34
active-directory-1.35
active-directory-1.36
active-directory-1.37
active-directory-1.38
active-directory-1.39
active-directory-1.40
active-directory-1.41
active-directory-1.42
active-directory-1.43
active-directory-1.44
active-directory-1.45
active-directory-1.46
active-directory-1.47
active-directory-1.48
active-directory-1.49

active-directory-2.*

active-directory-2.0
active-directory-2.1
active-directory-2.10
active-directory-2.2
active-directory-2.3
active-directory-2.4
active-directory-2.5
active-directory-2.6
active-directory-2.7
active-directory-2.8
active-directory-2.9