Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-3860: CVE-2021-3860: Artifactory Low Privileged Blind SQL Injection - JFrog

JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.

CVE
#sql

****How to fix******Cloud Environments**

Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self Hosted Environments

To fix this issue, there is required action.

Upgrade your version of Artifactory or Edge to one of the versions listed below:

****Workarounds and Mitigations****

You can mitigate the impact of this issue by following best practices and disabling anonymous access to the JFrog Platform. Please review the best practices for disabling anonymous access in the JFrog knowledge base.

Anonymous Access is disabled by default for new Artifactory and Edge installations starting from versions 6.12.0 and 7.0.0.

****Exploitation Status****

JFrog is not aware of publicly available exploits and malicious exploitation attempts.

****Weakness Type****

CWE-89: Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’).

****Acknowledgements****

This issue was discovered and reported by a JFrog customer.

****We Are Here For Your Questions (JFrog Support Team)****

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

  • No labels

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907