Description
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-28835 | JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation. |
References
History
No history.
Status: PUBLISHED
Assigner: JFROG
Published:
Updated: 2024-08-04T03:22:24.943Z
Reserved: 2022-02-14T00:00:00.000Z
Link: CVE-2021-41834
No data.
Status : Modified
Published: 2022-05-23T07:16:13.007
Modified: 2024-11-21T06:26:50.910
Link: CVE-2021-41834
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD