CVE-2023-42662: JFrog Artifactory Improper SSO Mechanism may lead to Exposure of Access Tokens
JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-42662?
CVE-2023-42662 has a medium severity rating due to the risk of user access token exposure.
How do I fix CVE-2023-42662?
To mitigate CVE-2023-42662, upgrade JFrog Artifactory to version 7.59.18, 7.63.18, 7.68.19, or 7.71.8 or later.
What versions of JFrog Artifactory are affected by CVE-2023-42662?
CVE-2023-42662 affects JFrog Artifactory versions 7.59 to below 7.59.18, 7.63.18, 7.68.19, and 7.71.8.
What kind of issue does CVE-2023-42662 represent?
CVE-2023-42662 represents an issue of improper handling of the CLI / IDE browser based SSO integration.
What impact does CVE-2023-42662 have on users?
CVE-2023-42662 can lead to the exposure of user access tokens, which can compromise user accounts.