← back
CVE-2024-4142

JFrog Artifactory Improper input validation within token creation flow

CVSS 9 CRITICALEPSS 0.7%CWE-20
An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
JFrog · Artifactory

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →