An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin.
References
Link | Resource |
---|---|
https://jenkins.io/security/advisory/2018-09-25/#SECURITY-265 | Vendor Advisory |
http://www.securityfocus.com/bid/106532 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2019-01-09 15:29
Updated : 2020-08-24 10:37
NVD link : CVE-2018-1000424
Mitre link : CVE-2018-1000424
JSON object : View
CWE
CWE-522
Insufficiently Protected Credentials
Products Affected
jfrog
- artifactory