CVE-2021-23163Cross-Site Request Forgery in Artifactory

Severity
8.8HIGHNVD
CNA3.1
EPSS
0.1%
top 69.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 6
Latest updateJul 7

Description

JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDjfrog/artifactory6.0.06.23.38+1
CVEListV5jfrog/jfrog_artifactoryJFrog Artifactory versions before 7.33.67.x+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-63vv-f5j8-wjcr: JFrog Artifactory prior to version 72022-07-07
CVEList
CVE-2021-23163: JFrog Artifactory prior to version 72022-07-06
CVE-2021-23163 — Cross-Site Request Forgery | cvebase