CVE-2023-42508Improper Input Validation in Artifactory

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 41.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 3

Description

JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5jfrog/artifactory7.0.07.66.0
NVDjfrog/artifactory7.0.07.66.0

🔴Vulnerability Details

2
CVEList
JFrog Artifactory Improper header input validation leads to email manipulation sent from the platform2023-10-03
GHSA
GHSA-mp3m-h3mq-83jw: JFrog Artifactory prior to version 72023-10-03
CVE-2023-42508 — Improper Input Validation | cvebase