Description
Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/11/15/4
https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2094
Related Vulnerabilities
CVE-2019-17592 Vulnerability in npm package csv-parse
CVE-2021-40690 Vulnerability in maven package org.apache.santuario:xmlsec
CVE-2022-26112 Vulnerability in maven package org.apache.pinot:pinot-spi
CVE-2023-49656 Vulnerability in maven package org.jenkins-ci.plugins:matlab
CVE-2022-36884 Vulnerability in maven package org.jenkins-ci.plugins:git