CVE-2021-3860SQL Injection in Artifactory

CWE-89SQL Injection3 documents3 sources
Severity
8.8HIGHNVD
EPSS
0.2%
top 51.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 20
Latest updateDec 21

Description

JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDjfrog/artifactory7.11.07.11.8+9
CVEListV5jfrog/jfrog_artifactoryJFrog Artifactory versions before 7.25.4 with E+ license7.25.4+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p7mv-x2rc-847f: JFrog Artifactory before 72021-12-21
CVEList
CVE-2021-3860: JFrog Artifactory before 72021-12-20
CVE-2021-3860 — SQL Injection in Jfrog Artifactory | cvebase