Unencrypted Password Storage in Jenkins Artifactory Plugin by CloudBees
CVE-2020-2164
6.5MEDIUM
What is CVE-2020-2164?
The Jenkins Artifactory Plugin prior to version 3.5.0 exposes sensitive information by storing the Artifactory server password in an unencrypted format within its global configuration file on the Jenkins master server. This flaw allows users with access to the Jenkins master file system to view the unprotected password, potentially compromising security.
Affected Version(s)
Jenkins Artifactory Plugin <= 3.5.0