An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users. Reverse Proxy Auth Plugin 1.6.0 and newer no longer store the cache of granted authorities on disk.
{
"cwe_ids": [
"CWE-200"
],
"github_reviewed": true,
"nvd_published_at": "2018-04-05T13:29:00Z",
"severity": "LOW",
"github_reviewed_at": "2022-12-12T21:26:03Z"
}