Описание
JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.
Уязвимые конфигурации
Конфигурация 1Версия от 7.59.0 (включая) до 7.59.18 (исключая)Версия от 7.63.5 (включая) до 7.63.18 (исключая)Версия от 7.68.7 (включая) до 7.68.19 (исключая)Версия от 7.71.2 (включая) до 7.71.8 (исключая)
Одно из
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
EPSS
Процентиль: 51%
0.00279
Низкий
9.3 Critical
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 9.3
github
почти 2 года назад
JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.
EPSS
Процентиль: 51%
0.00279
Низкий
9.3 Critical
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-287