Vulnerabilities > CVE-2019-19937 - Missing Authorization vulnerability in Jfrog Artifactory

047910
CVSS 7.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
jfrog
CWE-862

Summary

In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."

Vulnerable Configurations

Part Description Count
Application
Jfrog
384

Common Weakness Enumeration (CWE)