CVE-2022-23105 is a medium-severity vulnerability affecting Jenkins Active Directory Plugin versions 2.25 and earlier, where data transmission between the Jenkins controller and Active Directory servers is unencrypted in most configurations. This allows an unauthenticated attacker on the adjacent network (AV:A) to intercept sensitive information (C:H) without user interaction (UI:N), posing a significant confidentiality risk. Despite its potential impact, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB: None), and it has not been added to CISA's KEV catalog. Community discussion and media coverage are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.25CPE matchmatch criteria | cpe:2.3:a:jenkins:active_directory:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.