PT-2024-13052 · Jfrog · Jfrog Artifactory
Published
2024-03-07
·
Updated
2025-03-11
·
CVE-2023-42662
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
JFrog Artifactory versions 7.59 through 7.59.17
JFrog Artifactory versions 7.63 through 7.63.17
JFrog Artifactory versions 7.68 through 7.68.18
JFrog Artifactory versions 7.71 through 7.71.7
Description
The issue arises from improper handling of the CLI / IDE browser-based SSO integration, which could lead to exposure of user access tokens when users interact with specially crafted URLs.
Recommendations
For versions 7.59 through 7.59.17, update to version 7.59.18 or later.
For versions 7.63 through 7.63.17, update to version 7.63.18 or later.
For versions 7.68 through 7.68.18, update to version 7.68.19 or later.
For versions 7.71 through 7.71.7, update to version 7.71.8 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jfrog Artifactory