CVE-2022-0668: Critical severity jfrog artifactory vulnerability
JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-0668.
What is the severity of CVE-2022-0668?
The severity of CVE-2022-0668 is critical with a CVSS score of 9.8.
What is the affected software version range for this vulnerability?
JFrog Artifactory versions between 6.0.0 and 7.37.13 are affected by this vulnerability.
How can an unauthenticated user exploit this vulnerability?
An unauthenticated user can exploit this vulnerability by sending a specially crafted request which bypasses authentication and may lead to privilege escalation.
Where can I find more information about CVE-2022-0668?
More information about CVE-2022-0668 can be found at the following link: [CVE-2022-0668: Artifactory Authentication Bypass](https://www.jfrog.com/confluence/display/JFROG/CVE-2022-0668%3A+Artifactory+Authentication+Bypass)