Vulnerabilities > Jfrog > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-01-23 CVE-2020-7931 Unspecified vulnerability in Jfrog Artifactory
In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file.
network
low complexity
jfrog
6.5
2019-05-31 CVE-2019-10324 Cross-Site Request Forgery (CSRF) vulnerability in Jfrog Artifactory
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven projects, and promote previously staged builds, respectively.
network
low complexity
jfrog CWE-352
6.5
2019-05-31 CVE-2019-10323 Missing Authorization vulnerability in Jfrog Artifactory
A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
network
low complexity
jfrog CWE-862
4.3
2019-05-31 CVE-2019-10322 Missing Authorization vulnerability in Jfrog Artifactory
A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jfrog CWE-862
4.3
2019-05-31 CVE-2019-10321 Cross-Site Request Forgery (CSRF) vulnerability in Jfrog Artifactory
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jfrog CWE-352
4.3
2018-07-13 CVE-2018-1000206 Cross-Site Request Forgery (CSRF) vulnerability in Jfrog Artifactory
JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF attack allowing an attacker to perform actions as logged in user.
network
jfrog CWE-352
6.8
2018-07-09 CVE-2018-1000623 Path Traversal vulnerability in Jfrog Artifactory
JFrog JFrog Artifactory version Prior to version 6.0.3, since version 4.0.0 contains a Directory Traversal vulnerability in The "Import Repository from Zip" feature, available through the Admin menu -> Import & Export -> Repositories, triggers a vulnerable UI REST endpoint (/ui/artifactimport/upload) that can result in Directory traversal / file overwrite and remote code execution.
network
low complexity
jfrog CWE-22
6.5