Описание
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
Ссылки
- Release Notes
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.146.0 (включая) до 7.146.34 (исключая)Версия от 7.161.0 (включая) до 7.161.15 (исключая)
Одно из
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
EPSS
Процентиль: 14%
0.00232
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 6.5
github
11 дней назад
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
EPSS
Процентиль: 14%
0.00232
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-200