Executive brief
The Jenkins LDAP plugin, which allows Jenkins to use corporate directories for user login, contains a security flaw in how it handles server redirections. If an attacker can control the LDAP server or intercept network traffic, they can redirect Jenkins to a malicious server that triggers unauthorized code execution. This could allow an attacker to take full control of the Jenkins controller, potentially compromising the entire software delivery pipeline and sensitive credentials.
Technical details
The Jenkins LDAP Plugin (versions 807.v7d7de30930cf and earlier) fails to validate LDAP referrals, allowing them to point to arbitrary RMI URLs. When the plugin follows such a referral from a compromised or attacker-controlled LDAP server, it triggers the deserialization of untrusted data. If suitable 'gadget' classes are present on the Jenkins controller's classpath, this leads to Remote Code Execution (RCE). Exploitation requires the attacker to either control the configured LDAP server or perform a machine-in-the-middle (MitM) attack. The vulnerability is addressed in version 807.809.vd3a_4e5e4ec98 by disabling the following of LDAP referrals.
Affected products
- Jenkins LDAP Plugin <= 807.v7d7de30930cf
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory
- 2026-05-27: patched