CVE-2018-1000206
Published on: 07/13/2018 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:24:31 PM UTC
Certain versions of Artifactory from Jfrog contain the following vulnerability:
JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF attack allowing an attacker to perform actions as logged in user. This attack appear to be exploitable via The victim must run maliciously crafted flash component. This vulnerability appears to have been fixed in 6.1.
- CVE-2018-1000206 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Exploiting JSON Cross Site Request Forgery (CSRF) using Flash | Geekboy | Security Researcher | Exploit Third Party Advisory www.geekboy.ninja text/html |
![]() |
Release Notes - JFrog JIRA | Release Notes Vendor Advisory www.jfrog.com text/html |
![]() |
[RTFACT-17004] CSRF vulnerability with flash redirect - JFrog JIRA | Issue Tracking Patch Vendor Advisory www.jfrog.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Jfrog | Artifactory | All | All | All | All |
Application | Jfrog | Artifactory | All | All | All | All |
- cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*:
- cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*:
No vendor comments have been submitted for this CVE