Description
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- jfrog / artifactory0 – 7.146.8
- jfrog / artifactory0 – 7.111.20
- jfrog / artifactory7.117.0 – 7.117.27
- jfrog / artifactory7.125.0 – 7.125.19
- jfrog / artifactory7.133.0 – 7.133.28
- jfrog / artifactory7.146.0 – 7.146.8
- jfrog / artifactory7.111.20
Exploits & proofs of concept
- nucleiJFrog Artifactory - Anonymous Token Disclosure via Trailing Slash Auth Bypassby theamanrawat
Updated 9m ago · 8 sources