Vulnerabilities > Jfrog > Artifactory > 6.0.0

DATE CVE VULNERABILITY TITLE RISK
2018-07-13 CVE-2018-1000206 Cross-Site Request Forgery (CSRF) vulnerability in Jfrog Artifactory
JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF attack allowing an attacker to perform actions as logged in user.
network
jfrog CWE-352
6.8
2018-07-09 CVE-2018-1000623 Path Traversal vulnerability in Jfrog Artifactory
JFrog JFrog Artifactory version Prior to version 6.0.3, since version 4.0.0 contains a Directory Traversal vulnerability in The "Import Repository from Zip" feature, available through the Admin menu -> Import & Export -> Repositories, triggers a vulnerable UI REST endpoint (/ui/artifactimport/upload) that can result in Directory traversal / file overwrite and remote code execution.
network
low complexity
jfrog CWE-22
6.5