Description
Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/11/15/4
https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2094
Related Vulnerabilities
CVE-2019-0187 Vulnerability in maven package org.apache.jmeter:apachejmeter_core
CVE-2020-13920 Vulnerability in maven package org.apache.activemq:activemq-broker
CVE-2020-15999 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-43307 Vulnerability in npm package semver-regex
CVE-2013-4590 Vulnerability in maven package org.apache.tomcat:catalina