CVE-2018-1000424: High severity jfrog artifactory vulnerability
An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-1000424.
What is the severity of CVE-2018-1000424?
The severity of CVE-2018-1000424 is high with a CVSS score of 7.8.
Which software versions are affected by CVE-2018-1000424?
Jenkins Artifactory Plugin version 2.16.1 and earlier are affected by CVE-2018-1000424.
How can an attacker exploit CVE-2018-1000424?
An attacker with local file system access can exploit CVE-2018-1000424 to obtain old credentials configured for the Artifactory Plugin before it integrated with Credential Management in Jenkins.
Are there any references available for CVE-2018-1000424?
Yes, you can find more information about CVE-2018-1000424 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/106532) and [Jenkins Security Advisory](https://jenkins.io/security/advisory/2018-09-25/#SECURITY-265).