Jenkins Active Directory Plugin follows LDAP referrals by default
Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals from the configured Active Directory server by default. These can forward to an RMI URL that causes Jenkins to deserialize attacker-controlled data, resulting in Remote Code Execution (RCE) on the Jenkins controller if deserialization "gadgets" are available on the classpath. This allows attackers able to control the configured Active Directory server, or able to perform a machine-in-the-middle attack, to execute …