PT-2022-27486 · Jenkins · Jenkins Reverse Proxy Auth Plugin+1

Jesse Glick

·

Published

2022-11-15

·

Updated

2023-11-13

·

CVE-2022-45384

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Reverse Proxy Auth Plugin versions 1.7.3 and earlier
Description The issue allows attackers with access to the Jenkins controller file system to view the LDAP manager password, which is stored unencrypted in the global config.xml file.
Recommendations For Jenkins Reverse Proxy Auth Plugin versions 1.7.3 and earlier, update to a version that fixes the storage of the LDAP manager password to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-45384
GHSA-WCJJ-QM5V-J4PC

Affected Products

Jenkins
Jenkins Reverse Proxy Auth Plugin