CVE-2026-48917

Source
https://cve.org/CVERecord?id=CVE-2026-48917
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48917.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-48917
Aliases
Published
2026-05-27T15:16:31.347Z
Modified
2026-07-15T06:10:00.868484Z
Severity
  • 6.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.

References

Affected packages

Git / github.com/jenkinsci/ldap-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/ldap-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
Last affected
Database specific
{
    "cpe": [
        "cpe:2.3:a:jenkins:ldap:*:*:*:*:*:jenkins:*:*",
        "cpe:2.3:a:jenkins:ldap:807.v7d7de30930cf:*:*:*:*:jenkins:*:*"
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "793.v754d6b_41b_ea_4"
        },
        {
            "introduced": "807.v7d7de30930cf"
        },
        {
            "last_affected": "807.v7d7de30930cf"
        }
    ]
}

Affected versions

659.*
659.v8ca_b_a_fe79fa_d
671.*
671.v2a_9192a_7419d
673.*
673.v034ec70ec2b_b_
676.*
676.vfa_64cf6b_b_002
682.*
682.v7b_544c9d1512
694.*
694.vc02a_69c9787f
701.*
701.vf8619de9160a_
711.*
711.vb_d1a_491714dc
719.*
719.vcb_d039b_77d0d
725.*
725.v3cb_b_711b_1a_ef
733.*
733.vd3700c27b_043
753.*
753.v387f5b_3ea_8d0
756.*
756.v2f20b_801f120
759.*
759.vef7f616475df
764.*
764.v4d0d3599e9c2
770.*
770.vb_455e934581a_
776.*
776.vddf3e325103b_
780.*
780.vcb_33c9a_e4332
793.*
793.v754d6b_41b_ea_4
807.*
807.v7d7de30930cf
ldap-1.*
ldap-1.0
ldap-1.1
ldap-1.10
ldap-1.10.1
ldap-1.10.2
ldap-1.11
ldap-1.12
ldap-1.13
ldap-1.14
ldap-1.15
ldap-1.16
ldap-1.16-beta-1
ldap-1.16-beta-2
ldap-1.17
ldap-1.18
ldap-1.19
ldap-1.2
ldap-1.20
ldap-1.21
ldap-1.22
ldap-1.23
ldap-1.24
ldap-1.25
ldap-1.26
ldap-1.3
ldap-1.4
ldap-1.5
ldap-1.6
ldap-1.7
ldap-1.8
ldap-1.9
ldap-2.*
ldap-2.0
ldap-2.1
ldap-2.10
ldap-2.11
ldap-2.12
ldap-2.2
ldap-2.3
ldap-2.4
ldap-2.5
ldap-2.6
ldap-2.7
ldap-2.8
ldap-2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48917.json"