Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most configurations.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-1389 | vendor advisory |
http://www.openwall.com/lists/oss-security/2022/01/12/6 | third party advisory mailing list |