Description
A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
Remediation
References
Related Vulnerabilities
MySQL CVE-2020-14809 Vulnerability (CVE-2020-14809)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0050)
MySQL CVE-2014-0427 Vulnerability (CVE-2014-0427)
PHP Improper Input Validation Vulnerability (CVE-2006-7243)
Jenkins Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-27900)