Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-86pj-p9q6-88h5

Опубликовано: 03 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.

JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.

EPSS

Процентиль: 55%
0.0033
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
почти 4 года назад

JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.

EPSS

Процентиль: 55%
0.0033
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-863