Artifactory Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2019-10321 - Vulnerability Database

Artifactory Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2019-10321

Medium
Reference: CVE-2019-10321
Title: Artifactory Cross-Site Request Forgery (CSRF) Vulnerability
Overview:

A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpldoTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method capturing credentials stored in Jenkins.