CVE-2021-45074: Medium severity jfrog artifactory vulnerability
Published Mar 2, 2022
·Updated
JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.
Affected Software
2 affected components
JFrog Artifactory>=6.0.0<6.23.38
JFrog Artifactory>=7.0.0<7.29.3
Event History
Mar 2, 2022
CVE Published
via MITRE·09:20 PM
Data Sourced
via MITRE·09:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this JFrog Artifactory vulnerability?
The vulnerability ID of this JFrog Artifactory vulnerability is CVE-2021-45074.
2
What is the severity of CVE-2021-45074?
The severity of CVE-2021-45074 is medium with a CVSS score of 5.4.
3
What is the impact of CVE-2021-45074?
CVE-2021-45074 allows a low-privileged user to delete other known users' OAuth tokens, forcing reauthentication on an active session or in the next UI session.
4
Which versions of JFrog Artifactory are affected by CVE-2021-45074?
JFrog Artifactory versions before 7.29.3 and 6.23.38 are affected by CVE-2021-45074.
5
How can I fix CVE-2021-45074 in JFrog Artifactory?
To fix CVE-2021-45074 in JFrog Artifactory, you should upgrade to version 7.29.3 or 6.23.38 or later.