PT-2024-19445 · Jfrog · Jfrog Platform

Published

2024-05-15

·

Updated

2024-07-08

·

CVE-2024-2248

CVSS v3.1

6.4

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions JFrog platform versions prior to 7.85.0 (SaaS) JFrog platform versions prior to 7.84.7 (Self-Hosted)
Description A Header Injection issue may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s user email. This issue may also potentially allow remote code execution.
Recommendations For JFrog platform versions prior to 7.85.0 (SaaS), upgrade to version 7.85.0 or later. For JFrog platform versions prior to 7.84.7 (Self-Hosted), upgrade to version 7.84.7 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

BIT-ARTIFACTORY-2024-2248
CVE-2024-2248

Affected Products

Jfrog Platform