Lucene search

K
cveJFROGCVE-2021-46687
HistoryJul 06, 2022 - 10:15 a.m.

CVE-2021-46687

2022-07-0610:15:09
CWE-359
CWE-668
JFROG
web.nvd.nist.gov
1215
cve-2021-46687
jfrog artifactory
sensitive data exposure
project administrator rest api
nvd
security vulnerability

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

28.4%

JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.

Affected configurations

Nvd
Node
jfrogartifactoryRange6.0.06.23.38-
OR
jfrogartifactoryRange7.0.07.31.10-
VendorProductVersionCPE
jfrogartifactory*cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*

CNA Affected

[
  {
    "product": "JFrog Artifactory",
    "vendor": "JFrog",
    "versions": [
      {
        "lessThan": "7.x",
        "status": "affected",
        "version": "JFrog Artifactory versions before 7.31.10",
        "versionType": "custom"
      },
      {
        "lessThan": "6.x",
        "status": "affected",
        "version": "JFrog Artifactory versions before 6.23.38",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

28.4%

Related for CVE-2021-46687