Описание
Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
Ссылки
- Mailing ListThird Party Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.7.4 (исключая)
cpe:2.3:a:jenkins:reverse_proxy_auth:*:*:*:*:*:jenkins:*:*
EPSS
Процентиль: 73%
0.00752
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-522
CWE-522
Связанные уязвимости
CVSS3: 6.5
github
около 3 лет назад
Jenkins Reverse Proxy Auth Plugin vulnerable due to plaintext storage of passwords
EPSS
Процентиль: 73%
0.00752
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-522
CWE-522