CVE-2024-6915Improper Input Validation in Artifactory

Severity
9.3CRITICALNVD
EPSS
0.1%
top 76.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 5

Description

JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:LExploitability: 3.9 | Impact: 4.7

Affected Packages1 packages

CVEListV5jfrog/artifactory< 7.90.6+7

🔴Vulnerability Details

2
GHSA
GHSA-995f-jhr3-5x29: JFrog Artifactory versions below 72024-08-05
CVEList
JFrog Artifactory Cache Poisoning2024-08-05
CVE-2024-6915 — Improper Input Validation | cvebase