PT-2020-2658 · Jenkins · Jenkins Artifactory Plugin
Ethorsa
+1
·
Published
2020-03-25
·
Updated
2024-03-06
·
CVE-2020-2164
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Artifactory Plugin versions 3.5.0 and earlier
Description
The issue is related to the storage of the Artifactory server password in plain text in the global configuration file. This allows users with access to the Jenkins master file system to view the password. The vulnerability can be exploited by a remote attacker to obtain credentials. The password is stored unencrypted in the
org.jfrog.hudson.ArtifactoryBuilder.xml file.Recommendations
For Jenkins Artifactory Plugin versions 3.5.0 and earlier, update to version 3.6.0 or later, which stores the Artifactory server password encrypted.
As a temporary workaround, consider restricting access to the Jenkins controller file system to minimize the risk of exploitation.
Fix
Cleartext Storage of Sensitive Information
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins Artifactory Plugin