Broken Access Control in JFrog Artifactory Affects Multiple Versions
CVE-2021-41834

5.3MEDIUM

Key Information:

Vendor

Jfrog

Vendor
CVE Published:
23 May 2022

What is CVE-2021-41834?

JFrog Artifactory versions prior to 7.28.0 and 6.23.38 are susceptible to a Broken Access Control vulnerability. This flaw allows low-privileged users to exploit the copy functionality, enabling them to read and duplicate any artifact within the Artifactory deployment. The vulnerability stems from inadequate validation of permissions, which could lead to unauthorized access to sensitive artifacts.

Affected Version(s)

Artifactory 7.x < 7.28.0

Artifactory 6.x < 6.23.38

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.