Description
An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users.
Remediation
References
https://jenkins.io/security/advisory/2018-03-26/#SECURITY-736
Related Vulnerabilities
CVE-2022-36921 Vulnerability in maven package org.jenkins-ci.plugins:coverity
CVE-2021-21620 Vulnerability in maven package org.jenkins-ci.plugins:claim
CVE-2013-1966 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2019-1003064 Vulnerability in maven package org.jenkins-ci.plugins:aws-device-farm
CVE-2023-48292 Vulnerability in maven package org.xwiki.contrib:xwiki-application-admintools