PT-2022-12902 · Jfrog · Jfrog Artifactory

Published

2022-07-06

·

Updated

2024-03-06

·

CVE-2021-46687

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions JFrog Artifactory versions prior to 7.31.10 JFrog Artifactory versions prior to 6.23.38
Description The issue affects JFrog Artifactory, where sensitive data exposure can occur through the Project Administrator REST API.
Recommendations For versions prior to 7.31.10, update to version 7.31.10 or later. For versions prior to 6.23.38, update to version 6.23.38 or later. As a temporary workaround, consider restricting access to the Project Administrator REST API until a patch is available.

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BIT-ARTIFACTORY-2021-46687
CVE-2021-46687

Affected Products

Jfrog Artifactory