[JENKINS:SECURITY-1015-2] Users with Overall/Read access could enumerate credential IDs in `artifactory`

Severity Medium
Affected Packages 2
CVEs 1

artifactory provides a list of applicable credential IDs to allow users configuring the plugin to select the one to use.

This functionality does not correctly check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs.
Those can be used as part of an attack to capture the credentials using another vulnerability.

As of publication of this advisory, no release containing a fix is available.

ID
JENKINS:SECURITY-1015-2
Severity
medium
Published
2019-05-31T00:00:00
(5 years ago)
Modified
2019-05-31T00:00:00
(5 years ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository artifactory repository https://github.com/jenkinsci/artifactory-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/artifactory org.jenkins-ci.plugins artifactory <= 3.2.2
Affected pkg:github/jenkinsci/artifactory-plugin jenkinsci artifactory-plugin <= 3.2.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...