Description
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- jfrog / artifactory0 – 7.111.21
- jfrog / artifactory7.117.0 – 7.117.28
- jfrog / artifactory7.125.0 – 7.125.20
- jfrog / artifactory7.133.0 – 7.133.29
- jfrog / artifactory7.146.0 – 7.146.38
- jfrog / artifactory7.161.0 – 7.161.20
- jfrog / artifactory7.111.4 – 7.111.21
Exploits & proofs of concept
- nucleiJFrog Artifactory Access Blank Join Key Authentication Bypassby johnk3r,pruva
News coverage
- Hackers exploit critical JFrog Artifactory flaw to forge admin tokensBleepingComputer · 18d ago
- Attackers Pounce on Critical Artifactory Flaw Following DisclosureDark Reading · 19d ago
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureThe Hacker News · 19d ago
Updated 9m ago · 8 sources