CVE-2022-23105

MEDIUM4.8EPSS 0.01%

User passwords transmitted in plain text by Jenkins Active Directory Plugin

Published: 1/13/2022Modified: 2/16/2024

Description

Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most configurations.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.8CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

References (5)