CVE-2018-19971: Critical severity jfrog artifactory vulnerability
Published Apr 16, 2019
·Updated
JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.
Affected Software
1 affected component
JFrog Artifactory=6.5.9
Event History
Apr 16, 2019
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for JFrog Artifactory Pro 6.5.9?
The vulnerability ID for JFrog Artifactory Pro 6.5.9 is CVE-2018-19971.
2
What is the severity of CVE-2018-19971?
The severity of CVE-2018-19971 is critical with a CVSS score of 9.8.
3
What is the description of CVE-2018-19971?
CVE-2018-19971 is an Incorrect Access Control vulnerability in JFrog Artifactory Pro 6.5.9.
4
How does CVE-2018-19971 affect JFrog Artifactory Pro 6.5.9?
CVE-2018-19971 allows attackers to bypass access controls and gain unauthorized access to JFrog Artifactory Pro 6.5.9.
5
Are there any references related to CVE-2018-19971?
Yes, here are some references related to CVE-2018-19971: [1] http://packetstormsecurity.com/files/152137/JFrog-Artifactory-Pro-6.5.9-Signature-Validation.html, [2] http://seclists.org/fulldisclosure/2019/Mar/34, [3] http://www.securityfocus.com/bid/107518