Lucene search

K
cvelistJFROGCVELIST:CVE-2021-23163
HistoryJul 06, 2022 - 9:45 a.m.

CVE-2021-23163

2022-07-0609:45:12
CWE-352
JFROG
www.cve.org
4
jfrog artifactory
vulnerability
csrf
versions
7.33.6
6.23.38

CVSS3

3.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

31.8%

JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.

CNA Affected

[
  {
    "product": "JFrog Artifactory",
    "vendor": "JFrog",
    "versions": [
      {
        "lessThan": "7.x",
        "status": "affected",
        "version": "JFrog Artifactory versions before 7.33.6",
        "versionType": "custom"
      },
      {
        "lessThan": "6.x",
        "status": "affected",
        "version": "JFrog Artifactory versions before 6.23.38",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

3.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

31.8%

Related for CVELIST:CVE-2021-23163