PT-2022-13269 · Jfrog · Jfrog Artifactory

Published

2022-05-16

·

Updated

2024-03-06

·

CVE-2022-0573

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JFrog Artifactory versions prior to 7.36.1 JFrog Artifactory versions prior to 6.23.41
Description The issue is related to Insecure Deserialization of untrusted data. This can be exploited by a low-privileged authenticated user sending a specially crafted request, potentially leading to Denial of Service (DoS), Privilege Escalation, and Remote Code Execution due to insufficient validation of a user-provided serialized object.
Recommendations For versions prior to 7.36.1, update to version 7.36.1 or later. For versions prior to 6.23.41, update to version 6.23.41 or later.

Fix

DoS

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BIT-ARTIFACTORY-2022-0573
CVE-2022-0573

Affected Products

Jfrog Artifactory