CVE-2022-45384

Severity
6.5MEDIUM
EPSS
0.8%
top 26.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15
Latest updateNov 16

Description

Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Jenkins Reverse Proxy Auth Plugin vulnerable due to plaintext storage of passwords2022-11-16
OSV
Jenkins Reverse Proxy Auth Plugin vulnerable due to plaintext storage of passwords2022-11-16
CVEList
CVE-2022-45384: Jenkins Reverse Proxy Auth Plugin 12022-11-15

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2022-11-152022-11-15
CVE-2022-45384 (MEDIUM CVSS 6.5) | Jenkins Reverse Proxy Auth Plugin 1 | cvebase.io