Описание
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.
Ссылки
- Release Notes
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.111.18 (исключая)Версия от 7.117.0 (включая) до 7.117.25 (исключая)Версия от 7.125.0 (включая) до 7.125.18 (исключая)Версия от 7.133.0 (включая) до 7.133.27 (исключая)Версия от 7.146.0 (включая) до 7.146.34 (исключая)Версия от 7.161.0 (включая) до 7.161.15 (исключая)
Одно из
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
EPSS
Процентиль: 7%
0.00176
Низкий
7.1 High
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 7.1
github
11 дней назад
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.
EPSS
Процентиль: 7%
0.00176
Низкий
7.1 High
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-862