CVE-2021-41834: Medium severity jfrog artifactory vulnerability
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-41834?
CVE-2021-41834 is a vulnerability in JFrog Artifactory prior to version 7.28.0 and 6.23.38, where the copy functionality can be used by a low-privileged user to read and copy any artifact due to improper permissions validation.
How severe is CVE-2021-41834?
CVE-2021-41834 has a severity rating of 6.5 (Medium).
How does CVE-2021-41834 affect JFrog Artifactory?
CVE-2021-41834 affects JFrog Artifactory versions prior to 7.28.0 and 6.23.38.
How can a low-privileged user exploit CVE-2021-41834?
A low-privileged user can exploit CVE-2021-41834 by using the copy functionality to read and copy any artifact in the Artifactory deployment.
Is there a fix available for CVE-2021-41834?
Yes, the fix for CVE-2021-41834 is to upgrade JFrog Artifactory to version 7.28.0 or 6.23.38.