GHSA-fmjp-mw89-c6h6

Suggest an improvement
Source
https://github.com/advisories/GHSA-fmjp-mw89-c6h6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fmjp-mw89-c6h6/GHSA-fmjp-mw89-c6h6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fmjp-mw89-c6h6
Aliases
Published
2026-05-27T15:33:26Z
Modified
2026-07-01T19:56:31Z
Severity
  • 6.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Jenkins LDAP Plugin follows LDAP referrals
Details

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals from the configured LDAP server. These can forward to an RMI URL that causes Jenkins to deserialize attacker-controlled data, resulting in Remote Code Execution (RCE) on the Jenkins controller if deserialization "gadgets" are available on the classpath.

This allows attackers able to control the configured LDAP server, or able to perform a machine-in-the-middle attack, to execute code on the Jenkins controller.

LDAP Plugin 807.809.vd3a_4e5e4ec98 no longer follows LDAP referrals.

Database specific
{
    "cwe_ids":  [
        "CWE-918"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-01T19:37:42Z",
    "nvd_published_at":  "2026-05-27T15:16:31Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:ldap

Package

Name
org.jenkins-ci.plugins:ldap
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/ldap

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
807.809.vd3a

Affected versions

1.*
1.0
1.1
1.2
1.3
1.4
1.5
1.6
1.7
1.8
1.9
1.10
1.10.1
1.10.2
1.11
1.12
1.13
1.14
1.15
1.16-beta-1
1.16-beta-2
1.16
1.17
1.18
1.19
1.20
1.21
1.22
1.23
1.24
1.25
1.26
2.*
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2.10
2.10.1
2.11
2.12
659.*
659.v8ca_b_a_fe79fa_d
671.*
671.v2a_9192a_7419d
671.673.vc045dcdd856b_
673.*
673.v034ec70ec2b_b_
676.*
676.vfa_64cf6b_b_002
682.*
682.v7b_544c9d1512
694.*
694.vc02a_69c9787f
701.*
701.vf8619de9160a_
711.*
711.vb_d1a_491714dc
719.*
719.vcb_d039b_77d0d
725.*
725.v3cb_b_711b_1a_ef
733.*
733.vd3700c27b_043
753.*
753.v387f5b_3ea_8d0
756.*
756.v2f20b_801f120
759.*
759.vef7f616475df
764.*
764.v4d0d3599e9c2
770.*
770.vb_455e934581a_
776.*
776.vddf3e325103b_
780.*
780.vcb_33c9a_e4332
793.*
793.v754d6b_41b_ea_4
807.*
807.v7d7de30930cf

Database specific

last_known_affected_version_range
"<= 807.v7d7de30930cf"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fmjp-mw89-c6h6/GHSA-fmjp-mw89-c6h6.json"