CVE-2023-37943

CVE-2023-37943

Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active Directory credentials.

Source: CVE-2023-37943

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다