Lucene search

K
osvGoogleOSV:GHSA-CVH8-9J4X-5V4J
HistoryMay 13, 2022 - 1:18 a.m.

Jenkins Artifactory Plugin stored old directly entered credentials unencrypted on disk

2022-05-1301:18:46
Google
osv.dev
6
jenkins
artifactory plugin
credentials vulnerability
local file access

AI Score

6.5

Confidence

High

EPSS

0

Percentile

5.1%

An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin.

AI Score

6.5

Confidence

High

EPSS

0

Percentile

5.1%

Related for OSV:GHSA-CVH8-9J4X-5V4J