Vulnerabilities > CVE-2021-46687 - Exposure of Resource to Wrong Sphere vulnerability in Jfrog Artifactory

047910
CVSS 4.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
jfrog
CWE-668

Summary

JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.

Vulnerable Configurations

Part Description Count
Application
Jfrog
174

Common Weakness Enumeration (CWE)