Potential authentication bypass leading to privilege escalation in Artifactory
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 0.3%
from disclosure to weapon
Published on NVDJul 27
victimsJul 20
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
Appeared in 1 incident(s) we investigated
Hugging Face
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
jfrog · artifactory