8.8
CVE-2020-7931
- EPSS 33.48%
- Veröffentlicht 23.01.2020 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:38:02
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the DefaultObjectWrapper class makes certain Java functions accessible to a template.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jfrog ≫ Artifactory SwPlatform- Version < 5.11.8
Jfrog ≫ Artifactory SwPlatform- Version >= 6.0.0 < 6.1.6
Jfrog ≫ Artifactory SwPlatform- Version >= 6.2.0 < 6.3.9
Jfrog ≫ Artifactory SwPlatform- Version >= 6.4.0 < 6.7.8
Jfrog ≫ Artifactory Version >= 6.8.0 < 6.8.17
Jfrog ≫ Artifactory Version >= 6.9.0 < 6.9.6
Jfrog ≫ Artifactory Version >= 6.10.0 < 6.10.9
Jfrog ≫ Artifactory Version >= 6.11.0 < 6.11.7
Jfrog ≫ Artifactory Version >= 6.12.0 < 6.12.3
Jfrog ≫ Artifactory Version >= 6.13.0 < 6.13.2
Jfrog ≫ Artifactory Version >= 6.14.0 < 6.14.2
Jfrog ≫ Artifactory Version >= 6.15.0 < 6.15.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 33.48% | 0.968 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|