PT-2020-15533 · Jenkins · Jenkins Active Directory Plugin+1

Published

2020-11-04

·

Updated

2023-11-03

·

CVE-2020-2303

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Active Directory Plugin versions 2.19 and earlier
Description A cross-site request forgery (CSRF) issue allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials. This is due to the plugin not requiring POST requests for multiple HTTP endpoints implementing connection and authentication tests.
Recommendations For Jenkins Active Directory Plugin versions 2.19 and earlier, update to version 2.20 or later, which requires POST requests for the affected HTTP endpoints, mitigating the CSRF vulnerability.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2020-2303
GHSA-2WF5-4MF7-VMH3

Affected Products

Jenkins
Jenkins Active Directory Plugin