Описание
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.
Ссылки
- Release Notes
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.111.18 (исключая)Версия от 7.117.0 (включая) до 7.117.25 (исключая)Версия от 7.125.0 (включая) до 7.125.18 (исключая)Версия от 7.133.0 (включая) до 7.133.27 (исключая)Версия от 7.146.0 (включая) до 7.146.34 (исключая)Версия от 7.161.0 (включая) до 7.161.15 (исключая)
Одно из
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
EPSS
Процентиль: 12%
0.00215
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 6.5
github
11 дней назад
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.
EPSS
Процентиль: 12%
0.00215
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-918