Vulnerabilities > CVE-2019-10323 - Missing Authorization vulnerability in Jfrog Artifactory
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Talos
id | TALOS-2019-0846 |
last seen | 2019-06-04 |
published | 2019-06-04 |
reporter | Talos Intelligence |
source | http://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0846 |
title | Jenkins Artifactory Plugin fillCredentialsIdItems information disclosure vulnerability |
References
- http://www.openwall.com/lists/oss-security/2019/05/31/2
- http://www.openwall.com/lists/oss-security/2019/05/31/2
- http://www.securityfocus.com/bid/108540
- http://www.securityfocus.com/bid/108540
- https://jenkins.io/security/advisory/2019-05-31/#SECURITY-1015%20%282%29
- https://jenkins.io/security/advisory/2019-05-31/#SECURITY-1015%20%282%29
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0846
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0846