QID 731235
Date Published: 2024-03-08
QID 731235: JFrog Artifactory Sensitive Information Disclosure Vulnerability
JFrog Artifactory is the Universal Repository Manager supporting all major packaging formats, build tools and CI servers.
JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.
Affected Versions:
JFrog Artifactory versions from 7.59 prior to 7.59.18
JFrog Artifactory versions from 7.63 prior to 7.63.18
JFrog Artifactory versions from 7.68 prior to 7.68.19
JFrog Artifactory versions from 7.71 prior to 7.71.8
QID Detection Logic:
Unauthenticated: This QID checks for the version of Artifactory on the target.
Successful exploitation of this vulnerabilities may allow an attacker to access user access tokens due to improper handling of the CLI / IDE browser based SSO integration.
Block access to the CLI token exchange API endpoint: https://Artifactory-Host/access/api/v2/authentication/jfrog_client_login/token/*
- JFrog Artifactory Security Advisory -
jfrog.com/help/r/jfrog-release-information/cve-2023-42662-improper-sso-mechanism-may-lead-to-exposure-of-access-tokens
CVEs related to QID 731235
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JFrog Artifactory Security Advisory |
|