Security Advisory
CVE-2022-45384
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.