PT-2024-19440 · Jfrog · Jfrog Artifactory

Published

2024-03-13

·

Updated

2024-03-15

·

CVE-2024-2247

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JFrog Artifactory versions prior to 7.77.7 JFrog Artifactory versions prior to 7.82.1
Description The issue is related to DOM-based cross-site scripting due to improper handling of the import override mechanism.
Recommendations For versions prior to 7.77.7, update to version 7.77.7 or later. For versions prior to 7.82.1, update to version 7.82.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-ARTIFACTORY-2024-2247
CVE-2024-2247

Affected Products

Jfrog Artifactory