PT-2024-5363 · Jfrog · Jfrog Artifactory

Published

2024-08-05

·

Updated

2024-08-23

·

CVE-2024-6915

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions JFrog Artifactory versions prior to 7.90.6 JFrog Artifactory versions prior to 7.84.20 JFrog Artifactory versions prior to 7.77.14 JFrog Artifactory versions prior to 7.71.23 JFrog Artifactory versions prior to 7.68.22 JFrog Artifactory versions prior to 7.63.22 JFrog Artifactory versions prior to 7.59.23 JFrog Artifactory versions prior to 7.55.18
Description The issue is related to errors in processing input data, which can allow a remote attacker to perform a cache poisoning attack.
Recommendations For versions prior to 7.90.6, update to version 7.90.6 or later. For versions prior to 7.84.20, update to version 7.84.20 or later. For versions prior to 7.77.14, update to version 7.77.14 or later. For versions prior to 7.71.23, update to version 7.71.23 or later. For versions prior to 7.68.22, update to version 7.68.22 or later. For versions prior to 7.63.22, update to version 7.63.22 or later. For versions prior to 7.59.23, update to version 7.59.23 or later. For versions prior to 7.55.18, update to version 7.55.18 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05996
BIT-ARTIFACTORY-2024-6915
CVE-2024-6915

Affected Products

Jfrog Artifactory