CVE-2020-2165
HIGHJfrog Artifactory < 3.6.0 - Insufficiently Protected Credentials
Title source: ruleDescription
Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
Scores
CVSS v3
7.5
EPSS
0.0033
EPSS Percentile
55.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
Status
published
Affected Products (2)
jfrog/artifactory
< 3.6.0
org.jenkins-ci.plugins/artifactory
< 3.6.1Maven
Timeline
Published
Mar 25, 2020
Tracked Since
Feb 18, 2026