Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9j2-grqf-fg26

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 3.3

Описание

Jenkins Reverse Proxy Auth Plugin allows attackers with local file system access to obtain a list of authorities for logged in users

An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users. Reverse Proxy Auth Plugin 1.6.0 and newer no longer store the cache of granted authorities on disk.

Пакеты

Наименование

org.jenkins-ci.plugins:reverse-proxy-auth-plugin

maven
Затронутые версииВерсия исправления

<= 1.5

1.6.0

EPSS

Процентиль: 1%
0.00009
Низкий

3.3 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.3
nvd
почти 8 лет назад

An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users.

EPSS

Процентиль: 1%
0.00009
Низкий

3.3 Low

CVSS3

Дефекты

CWE-200