← Back

CVE-2021-41834

nvd nist
Published: May 23, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.

Affected (2)

Products: Jfrog: Artifactory
1 product
Artifactory
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Jfrog
Before 6.23.38
From 7.0.0 to 7.28.0

Timeline

No history available yet.