Broken Access Control in JFrog Artifactory Affects Project Admins
CVE-2021-46270

2.7LOW

Key Information:

Vendor

Jfrog

Vendor
CVE Published:
2 March 2022

What is CVE-2021-46270?

JFrog Artifactory, prior to version 7.31.10, has a vulnerability that allows project admin users to enumerate all repository names. This occurs due to inadequate permission validation, which can lead to unauthorized access to sensitive information about repositories. Organizations using this version of Artifactory should address this issue promptly to enhance the security of their environment.

Affected Version(s)

JFrog Artifactory JFrog Artifactory versions before 7.31.10 < 7.31.10

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.