First published: Wed Mar 02 2022(Updated: )
JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.
Credit: reefs@jfrog.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jfrog Artifactory | >=6.0.0<6.23.38 | |
Jfrog Artifactory | >=7.0.0<7.29.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this JFrog Artifactory vulnerability is CVE-2021-45074.
The severity of CVE-2021-45074 is medium with a CVSS score of 5.4.
CVE-2021-45074 allows a low-privileged user to delete other known users' OAuth tokens, forcing reauthentication on an active session or in the next UI session.
JFrog Artifactory versions before 7.29.3 and 6.23.38 are affected by CVE-2021-45074.
To fix CVE-2021-45074 in JFrog Artifactory, you should upgrade to version 7.29.3 or 6.23.38 or later.