PT-2022-12372 · Jfrog · Jfrog Artifactory

Published

2022-07-06

·

Updated

2024-03-06

·

CVE-2021-45721

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions JFrog Artifactory versions prior to 7.29.8 JFrog Artifactory versions prior to 6.23.38
Description The issue is related to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in the "Users REST API endpoint".
Recommendations For JFrog Artifactory versions prior to 7.29.8, update to version 7.29.8 or later. For JFrog Artifactory versions prior to 6.23.38, update to version 6.23.38 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-ARTIFACTORY-2021-45721
CVE-2021-45721

Affected Products

Jfrog Artifactory