An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-01-09T23:00:00

Updated: 2019-01-14T10:57:01

Reserved: 2019-01-09T00:00:00


Link: CVE-2018-1000424

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-01-09T23:29:02.920

Modified: 2020-08-24T17:37:01.140


Link: CVE-2018-1000424

JSON object: View

cve-icon Redhat Information

No data.

CWE