CVE-2020-2165

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.18 % (55th)
0.18% Progress
Affected Products 1
Advisories 2

Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

Weaknesses
CWE-522
Insufficiently Protected Credentials
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2020-03-25 17:15:15
(4 years ago)
Updated Date
2023-10-25 18:16:33
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jfrog Artifactory for Jenkins 3.6.0 and prior versions cpe:2.3:a:jfrog:artifactory::*:*:*:*:jenkins <= 3.6.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...