PT-2018-9476 · Jfrog · Jfrog Artifactory

Publicado

2018-07-09

·

Atualizado

2018-09-11

·

CVE-2018-1000623

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JFrog Artifactory versions prior to 6.0.3
Description The issue concerns a Directory Traversal vulnerability in the "Import Repository from Zip" feature, accessible through the Admin menu -> Import & Export -> Repositories. This feature triggers a vulnerable UI REST endpoint (/ui/artifactimport/upload) that can result in directory traversal, file overwrite, and remote code execution. An attacker with Admin privileges may exploit the publicly known "Zip Slip" vulnerability to add or overwrite files outside the target directory.
Recommendations For versions prior to 6.0.3, update to version 6.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the "Import Repository from Zip" feature and the /ui/artifactimport/upload endpoint to minimize the risk of exploitation.

Correção

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000623

Produtos afetados

Jfrog Artifactory