← Back

CVE-2021-3860

nvd nist
Published: Dec 20, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.

Affected (10)

Products: Jfrog: Artifactory
1 product
Artifactory
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Jfrog
Before 6.23.30
From 7.11.0 to 7.11.8
From 7.12.0 to 7.12.10
From 7.17.0 to 7.17.14
From 7.18.0 to 7.18.11
From 7.19.0 to 7.19.12
From 7.21.0 to 7.21.14
From 7.23.0 to 7.23.8
From 7.24.0 to 7.24.7
From 7.25.0 to 7.25.4

Timeline

No history available yet.