CVE-2024-2247: JFrog Artifactory Cross-Site Scripting
Published Mar 13, 2024
·Updated
JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.
Affected Software
2 affected components
JFrog Artifactory<7.77.7, <7.82.1
JFrog Artifactory<=7.77.7
Event History
Mar 13, 2024
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-2247?
CVE-2024-2247 has been classified as a medium severity vulnerability due to its risk of DOM-based cross-site scripting.
2
How do I fix CVE-2024-2247?
To mitigate CVE-2024-2247, upgrade JFrog Artifactory to version 7.77.7 or 7.82.1 or newer.
3
Which versions of JFrog Artifactory are affected by CVE-2024-2247?
CVE-2024-2247 affects JFrog Artifactory versions below 7.77.7 and 7.82.1.
4
What type of vulnerability is CVE-2024-2247?
CVE-2024-2247 is a DOM-based cross-site scripting vulnerability.
5
Can I exploit CVE-2024-2247 without authentication?
Yes, CVE-2024-2247 can potentially be exploited without requiring authentication.