Severity
7.5HIGH
EPSS
0.3%
top 43.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMay 24

Description

Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

3
OSV
Passwords transmitted in plain text by Jenkins Artifactory Plugin2022-05-24
GHSA
Passwords transmitted in plain text by Jenkins Artifactory Plugin2022-05-24
CVEList
CVE-2020-2165: Jenkins Artifactory Plugin 32020-03-25

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2020-03-252020-03-25
CVE-2020-2165 (HIGH CVSS 7.5) | Jenkins Artifactory Plugin 3.6.0 an | cvebase.io