Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vf92-j6mr-cjmj

Опубликовано: 07 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.3

Описание

JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.

JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.

EPSS

Процентиль: 51%
0.00279
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.3
nvd
почти 2 года назад

JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.

EPSS

Процентиль: 51%
0.00279
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-287