PT-2020-2653 · Jenkins · Jenkins Artifactory Plugin
Ethorsa
+1
·
Published
2020-03-25
·
Updated
2024-03-06
·
CVE-2020-2165
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Artifactory Plugin versions 3.6.0 and earlier
Description
The issue is related to the transmission of configured passwords in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. This can lead to the exposure of passwords through browser extensions, cross-site scripting vulnerabilities, and similar situations. The password is stored encrypted on disk since Artifactory Plugin 3.6.0, but it is transmitted in plain text by versions 3.6.0 and earlier.
Recommendations
For Jenkins Artifactory Plugin versions 3.6.0 and earlier, update to version 3.6.1 or later, which transmits the password in its global configuration encrypted. As a temporary workaround, consider restricting access to the global configuration form to minimize the risk of exploitation. Avoid using the
org.jfrog.hudson.ArtifactoryBuilder.xml configuration file until the issue is resolved.Fix
Cleartext Transmission of Sensitive Information
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins Artifactory Plugin