6.5
CVSSv3

CVE-2022-45384

Published: 15/11/2022 Updated: 13/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Jenkins Reverse Proxy Auth Plugin 1.7.3 and previous versions stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins reverse proxy auth