Description
A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
Remediation
References
Related Vulnerabilities
WordPress Plugin Storefront Footer Text Cross-Site Scripting (1.0.1)
WordPress Plugin GB Gallery Slideshow SQL Injection (1.2)
MySQL CVE-2019-2808 Vulnerability (CVE-2019-2808)
WordPress Plugin Clever Addons for Elementor Multiple Cross-Site Scripting Vulnerabilities (2.0.15)
WordPress Plugin Church Admin Arbitrary File Upload (1.2530)