CVE-2021-46687: Medium severity jfrog artifactory vulnerability
JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-46687?
CVE-2021-46687 is a vulnerability in JFrog Artifactory that allows sensitive data exposure through the Project Administrator REST API.
How does CVE-2021-46687 impact JFrog Artifactory?
CVE-2021-46687 affects JFrog Artifactory versions prior to 7.31.10 and 6.23.38.
What is the severity of CVE-2021-46687?
CVE-2021-46687 has a severity rating of medium (4.9).
How can I fix CVE-2021-46687?
To fix CVE-2021-46687, update JFrog Artifactory to version 7.31.10 or 6.23.38 or later.
Where can I find more information about CVE-2021-46687?
You can find more information about CVE-2021-46687 at the following references: - [JFrog CVE-2021-46687: Sensitive data exposure on proxy endpoint for Project Admin](https://www.jfrog.com/confluence/display/JFROG/CVE-2021-46687%3A+Sensitive+data+exposure+on+proxy+endpoint+for+Project+Admin) - [JFrog Security Advisories](https://www.jfrog.com/confluence/display/JFROG/JFrog+Security+Advisories)