-
CVSS Score
-The vulnerability description explicitly identifies ReverseProxySecurityRealm#authContext as the component that improperly stored sensitive authorities data on disk. The patched version 1.6.0 specifically addressed this by ceasing disk storage of this cache. While exact method names aren't shown in advisory text, the authContext component is directly implicated as the persistence mechanism for the vulnerable cache, making it the clear focal point of the exposure.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:reverse-proxy-auth-plugin | maven | <= 1.5 | 1.6.0 |