CVE-2021-46687Exposure of Private Personal Information to an Unauthorized Actor in Artifactory

Severity
4.9MEDIUMNVD
EPSS
0.3%
top 51.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 6
Latest updateJul 7

Description

JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

NVDjfrog/artifactory6.0.06.23.38+1
CVEListV5jfrog/jfrog_artifactoryJFrog Artifactory versions before 7.31.107.x+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3f45-mmr7-7f4p: JFrog Artifactory prior to version 72022-07-07
CVEList
CVE-2021-46687: JFrog Artifactory prior to version 72022-07-06
CVE-2021-46687 — Jfrog Artifactory vulnerability | cvebase