An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users. Reverse Proxy Auth Plugin 1.6.0 and newer no longer store the cache of granted authorities on disk.
{ "nvd_published_at": "2018-04-05T13:29:00Z", "github_reviewed_at": "2022-12-12T21:26:03Z", "severity": "LOW", "github_reviewed": true, "cwe_ids": [ "CWE-200" ] }