Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rq6c-pcm6-q4r9

Опубликовано: 20 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.

JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.

EPSS

Процентиль: 38%
0.00164
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6
nvd
больше 3 лет назад

JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.

EPSS

Процентиль: 38%
0.00164
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-863