12 Total advisories
12 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.jenkins-ci.plugins:active-directory is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
LOW 3.7
CVE-2026-57288
Jenkins Active Directory Plugin has an LDAP injection vulnerability
MEDIUM 6.6
CVE-2026-48919
Jenkins Active Directory Plugin deserializes data from LDAP referrals without validation
MEDIUM 6.6
CVE-2026-48918
Jenkins Active Directory Plugin follows LDAP referrals by default
HIGH 8.1
CVE-2017-2649
Jenkins Active Directory Plugin did not verify certificate of AD server
CRITICAL 9.8
CVE-2020-2301
Authentication cache in Active Directory Jenkins Plugin allows logging in with any password
MEDIUM 4.3
CVE-2020-2302
Missing permission check in Jenkins Active Directory Plugin allows accessing domain health check page
MEDIUM 4.3
CVE-2020-2303
CSRF vulnerability in Jenkins Active Directory Plugin
CRITICAL 9.8
CVE-2020-2299
Improper Authentication in Jenkins Active Directory Plugin
CRITICAL 9.8
CVE-2020-2300
Improper Authentication (empty password) in Jenkins Active Directory Plugin
MEDIUM 5.9
CVE-2023-37943
Jenkins Active Directory Plugin vulnerable to Active Directory credential disclosure
MEDIUM 4.8
CVE-2022-23105
User passwords transmitted in plain text by Jenkins Active Directory Plugin
HIGH 7.4
CVE-2019-1003009
Jenkins Active Directory Plugin Improper certificate validation with StartTLS
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes