CRITICAL9.8CVE-2020-2300Improper Authentication (empty password) in Jenkins Active Directory Plugin >= 2.17, < 2.20
CRITICAL9.8CVE-2020-2301Authentication cache in Active Directory Jenkins Plugin allows logging in with any password >= 2.17, < 2.20
CRITICAL9.8CVE-2020-2299Improper Authentication in Jenkins Active Directory Plugin >= 2.17, < 2.20
HIGH8.1Jenkins Active Directory Plugin did not verify certificate of AD server
from 0, < 2.3
HIGH7.4Jenkins Active Directory Plugin Improper certificate validation with StartTLS
from 0, < 2.11
MEDIUM6.6Jenkins Active Directory Plugin deserializes data from LDAP referrals without validation
from 0, < 2.41.1
MEDIUM6.6Jenkins Active Directory Plugin follows LDAP referrals by default
from 0, < 2.41.1
MEDIUM5.9Jenkins Active Directory Plugin vulnerable to Active Directory credential disclosure
from 0, < 2.30.1
MEDIUM4.8User passwords transmitted in plain text by Jenkins Active Directory Plugin
from 0, < 2.25.1
MEDIUM4.3CSRF vulnerability in Jenkins Active Directory Plugin
from 0, < 2.20
MEDIUM4.3Missing permission check in Jenkins Active Directory Plugin allows accessing domain health check page
from 0, < 2.20