PT-2020-2658 · Jenkins · Jenkins Artifactory Plugin

Ethorsa

+1

·

Published

2020-03-25

·

Updated

2024-03-06

·

CVE-2020-2164

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Artifactory Plugin versions 3.5.0 and earlier
Description The issue is related to the storage of the Artifactory server password in plain text in the global configuration file. This allows users with access to the Jenkins master file system to view the password. The vulnerability can be exploited by a remote attacker to obtain credentials. The password is stored unencrypted in the org.jfrog.hudson.ArtifactoryBuilder.xml file.
Recommendations For Jenkins Artifactory Plugin versions 3.5.0 and earlier, update to version 3.6.0 or later, which stores the Artifactory server password encrypted. As a temporary workaround, consider restricting access to the Jenkins controller file system to minimize the risk of exploitation.

Fix

Cleartext Storage of Sensitive Information

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2020-02702
BIT-ARTIFACTORY-2020-2164
CVE-2020-2164
GHSA-4Q47-PH87-FQ4F

Affected Products

Jenkins Artifactory Plugin