CVE-2024-4142Improper Input Validation in Artifactory

Severity
9.0CRITICALNVD
EPSS
0.8%
top 26.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 1

Description

An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 2.2 | Impact: 6.0

Affected Packages1 packages

CVEListV5jfrog/artifactory0 7.71.21+6

🔴Vulnerability Details

2
CVEList
JFrog Artifactory Improper input validation within token creation flow2024-05-01
GHSA
GHSA-h9vw-8427-h758: An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory2024-05-01
CVE-2024-4142 — Improper Input Validation | cvebase