Description
Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2094
http://www.openwall.com/lists/oss-security/2022/11/15/4
Related Vulnerabilities
CVE-2019-10409 Vulnerability in maven package hudson.plugins:project-inheritance
CVE-2012-0818 Vulnerability in maven package org.jboss.resteasy:resteasy-jettison-provider
CVE-2016-3506 Vulnerability in maven package com.oracle:ojdbc7
CVE-2022-36084 Vulnerability in npm package cruddl
CVE-2019-20363 Vulnerability in maven package org.igniterealtime.openfire:xmppserver