QID 997290

Date Published: 2024-02-20

QID 997290: Java (Maven) Security Update for org.jenkins-ci.plugins:artifactory (GHSA-cvh8-9j4x-5v4j)

An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Refer to Github security advisory GHSA-cvh8-9j4x-5v4j for updates and patch information.
    Vendor References

    CVEs related to QID 997290

    Software Advisories
    Advisory ID Software Component Link
    GHSA-cvh8-9j4x-5v4j org.jenkins-ci.plugins:artifactory URL Logo github.com/advisories/GHSA-cvh8-9j4x-5v4j