First published: Thu Apr 05 2018(Updated: )
An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins | <=1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000150 is classified as a medium severity vulnerability.
To mitigate CVE-2018-1000150, upgrade to Reverse Proxy Auth Plugin version 1.6 or later.
Failing to address CVE-2018-1000150 could allow attackers with local access to gain sensitive information about user authorities.
Jenkins Reverse Proxy Auth Plugin versions 1.5 and older are affected by CVE-2018-1000150.
Yes, CVE-2018-1000150 can affect Jenkins installations where the Reverse Proxy Auth Plugin is used, regardless of configuration.