ZeroHour

CVE-2020-2164

CVSS 3.1
6.5 medium
EPSS
<1%p55
Published
()
Modified
Description

Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.

Vendors
jfrog
Products
artifactory
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.