QID 731273
Date Published: 2024-03-21
QID 731273: JFrog Artifactory Authenticated Remote Code Execution (RCE) Vulnerability
JFrog Artifactory is the Universal Repository Manager supporting all major packaging formats, build tools and CI servers.
JFrog Artifactory 7.x prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.
Affected Versions:
JFrog Artifactory 7.x versions prior to 7.76.2
QID Detection Logic:
Unauthenticated: This QID checks for the version of Artifactory on the target using Server Header in response.
Successful exploitation of this vulnerability may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user.
- JFrog Artifactory Security Advisory -
jfrog.com/help/r/jfrog-release-information/cve-2023-42661-jfrog-artifactory-improper-input-validation-leads-to-arbitrary-file-write
CVEs related to QID 731273
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JFrog Artifactory Security Advisory |
|