Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8wcw-cw2f-h4g2

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Improper Authentication (empty password) in Jenkins Active Directory Plugin

Jenkins Active Directory Plugin implements two separate modes: Integration with ADSI on Windows, and an OS agnostic LDAP-based mode.

The Windows/ADSI mode does not specifically prohibit use of empty passwords in Active Directory Plugin prior to 2.20 and 2.16.1. If the Active Directory server allows the unauthenticated bind operation, this allows attackers to log in to Jenkins as any user by providing an empty password.

Jenkins Active Directory Plugin 2.20 and 2.16.1 prohibits the use of an empty password to log in.

Пакеты

Наименование

org.jenkins-ci.plugins:active-directory

maven
Затронутые версииВерсия исправления

>= 2.17, < 2.20

2.20

Наименование

org.jenkins-ci.plugins:active-directory

maven
Затронутые версииВерсия исправления

< 2.16.1

2.16.1

EPSS

Процентиль: 41%
0.00191
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configuration of the Active Directory server.

EPSS

Процентиль: 41%
0.00191
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287