Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-41834: CVE-2021-41834: Artifactory Broken Access Control on Copy Artifact - JFrog

JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.

CVE

****How to fix******Cloud Environments**

Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self Hosted Environments

To fix this issue, there is required action.

Upgrade your version of Artifactory or Edge to one of the versions listed below:

****Workarounds and Mitigations****

There aren’t any suggested workarounds to this issue besides upgrading to a fixed version.

****Weakness Type****

CWE-284: Improper Access Control

****Acknowledgements****

Maxime Escourbiac and Maxence Schmitt at Michelin CERT.

****We Are Here For Your Questions (JFrog Support Team)****

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

Related news

CVE-2022-0573: JFrog Security Advisories - JFrog

JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized object.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907