Description
Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/11/15/4
https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2094
Related Vulnerabilities
CVE-2022-23181 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2020-36183 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-37954 Vulnerability in maven package com.sonyericsson.hudson.plugins.rebuild:rebuild
CVE-2020-28458 Vulnerability in maven package org.webjars.bower:datatables.net
CVE-2016-9879 Vulnerability in maven package org.springframework.security:spring-security-web