CVE Tools

Jenkins Active Directory Plugin

11 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Jenkins Active Directory Plugin, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Jenkins Active Directory Plugin CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Jenkins Active Directory Plugin CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-052
2026-061
2026-070
2026-080
2026-090

Severity

How the 11 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical327%
  • High19%
  • Medium655%
  • Low19%

Latest CVEs

The 11 most recently published vulnerabilities affecting Jenkins Active Directory Plugin.

  1. CVE-2026-57288Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated at...3.7
  2. CVE-2026-48919Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.6.6
  3. CVE-2026-48918Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.6.6
  4. CVE-2023-37943Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to...5.9
  5. CVE-2022-23105Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most configurations.6.5
  6. CVE-2020-2303A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously co...4.3
  7. CVE-2020-2301Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is still in the optional cache when using Wi...9.8
  8. CVE-2020-2302A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page.4.3
  9. CVE-2020-2299Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.9.8
  10. CVE-2020-2300Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the config...9.8
  11. CVE-2019-1003009An improper certificate validation vulnerability exists in Jenkins Active Directory Plugin 2.10 and earlier in src/main/java/hudson/plugins/active_directory/ActiveDirectoryDomain.java, src/main/jav...7.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store