Vulnerability Description
Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configuration of the Active Directory server.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Active Directory | <= 2.19 |
References
- http://www.openwall.com/lists/oss-security/2020/11/04/6Mailing ListThird Party Advisory
- https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-2099Vendor Advisory
- http://www.openwall.com/lists/oss-security/2020/11/04/6Mailing ListThird Party Advisory
- https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-2099Vendor Advisory
FAQ
What is CVE-2020-2300?
CVE-2020-2300 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configura...
How severe is CVE-2020-2300?
CVE-2020-2300 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-2300?
Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Active Directory.