CVE-2019-10323: Medium severity jfrog artifactory vulnerability
A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
Other sources
Jenkins Artifactory Plugin provides a list of applicable credential IDs to allow users configuring the plugin to select the one to use.
This functionality does not correctly check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those can be used as part of an attack to capture the credentials using another vulnerability.
As of publication of this advisory, no release containing a fix is available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10323?
The severity of CVE-2019-10323 is medium, with a severity value of 4.3.
How does CVE-2019-10323 affect Jfrog Artifactory?
CVE-2019-10323 affects Jfrog Artifactory version 3.2.3 and earlier.
What is the impact of CVE-2019-10323?
CVE-2019-10323 allows any user with Overall/Read permission to view a list of valid credential IDs in Jenkins Artifactory Plugin.
Are there any known fixes for CVE-2019-10323?
Yes, upgrading to a version later than 3.2.3 of Jenkins Artifactory Plugin can fix CVE-2019-10323.
Where can I find more information about CVE-2019-10323?
You can find more information about CVE-2019-10323 at the following references: - http://www.openwall.com/lists/oss-security/2019/05/31/2 - http://www.securityfocus.com/bid/108540 - https://jenkins.io/security/advisory/2019-05-31/#SECURITY-1015%20(2)