Artifactory Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2019-10321
Reference:
CVE-2019-10321
Title:
Artifactory Cross-Site Request Forgery (CSRF) Vulnerability
Overview:
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpldoTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method capturing credentials stored in Jenkins.