CVE-2020-2300

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 7.5 (High)
75% Progress
EPSS 0.24 % (65th)
0.24% Progress
Affected Products 1
Advisories 2

Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configuration of the Active Directory server.

CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2020-11-04 15:15:11
(3 years ago)
Updated Date
2023-10-25 18:16:42
(10 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Active Directory for Jenkins 2.19 and prior versions cpe:2.3:a:jenkins:active_directory::*:*:*:*:jenkins <= 2.19
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...