GHSA-m9j2-grqf-fg26
Dashboard / Vulnerabilities / GHSA-m9j2-grqf-fg26
Summary: Jenkins Reverse Proxy Auth Plugin allows attackers with local file system access to obtain a list of authorities for logged in users
Details: An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users. Reverse Proxy Auth Plugin 1.6.0 and newer no longer store the cache of granted authorities on disk.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-1000150, https://github.com/jenkinsci/reverse-proxy-auth-plugin, https://jenkins.io/security/advisory/2018-03-26/#SECURITY-736
Affected packages
Package
Name: org.jenkins-ci.plugins:reverse-proxy-auth-plugin
Purl: pkg:maven/org.jenkins-ci.plugins/reverse-proxy-auth-plugin
Affected ranges
Type: ECOSYSTEM
Events:
