CVE-2021-46270: Medium severity jfrog artifactory vulnerability
Published Mar 2, 2022
·Updated
JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.
Affected Software
1 affected component
JFrog Artifactory>=7.0.0<7.31.10
Event History
Mar 2, 2022
CVE Published
via MITRE·09:20 PM
Data Sourced
via MITRE·09:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-46270?
CVE-2021-46270 is a vulnerability in JFrog Artifactory before version 7.31.10, which allows a project admin user to list all available repository names due to insufficient permission validation.
2
How does CVE-2021-46270 affect JFrog Artifactory?
CVE-2021-46270 affects JFrog Artifactory versions before 7.31.10 and allows project admin users to view all available repository names.
3
What is the severity of CVE-2021-46270?
The severity of CVE-2021-46270 is medium with a CVSS score of 2.7.
4
How can I fix CVE-2021-46270 in JFrog Artifactory?
To fix CVE-2021-46270, update JFrog Artifactory to version 7.31.10 or later.
5
Where can I find more information about CVE-2021-46270?
More information about CVE-2021-46270 can be found on the JFrog Artifactory website.