CVE-2017-2649: Jenkins Active Directory
High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
Affected products
- Jenkins Active Directory: up to and including 2.2
Published 2018-07-27. Last modified 2026-06-17.