CVE-2016-10036: Malicious File Upload
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-10036?
CVE-2016-10036 is an unrestricted file upload vulnerability in JFrog Artifactory before version 4.16.
How does CVE-2016-10036 vulnerability affect JFrog Artifactory?
The vulnerability allows remote attackers to deploy an arbitrary servlet application and execute arbitrary code or write to arbitrary files, potentially causing a denial of service.
What is the severity of CVE-2016-10036?
CVE-2016-10036 has a severity rating of 9.8 (critical).
How can I fix the CVE-2016-10036 vulnerability in JFrog Artifactory?
To fix the vulnerability, update JFrog Artifactory to version 4.16 or later.
Where can I find more information about CVE-2016-10036 and its fix?
More information about CVE-2016-10036 can be found in the JFrog Artifactory Release Notes and the provided references.