CVE-2019-9733
- EPSS 93.08%
- Veröffentlicht 11.04.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:52:11
An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connectio...
CVE-2018-1000424
- EPSS 0.04%
- Veröffentlicht 09.01.2019 23:29:02
- Zuletzt bearbeitet 21.11.2024 03:40:02
An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured ...
CVE-2018-1000206
- EPSS 0.21%
- Veröffentlicht 13.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:56
JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF attack allowing an attacker to perform actions as logged in user. This attack appear to be exploitable...
CVE-2018-1000623
- EPSS 1.02%
- Veröffentlicht 09.07.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:15
JFrog JFrog Artifactory version Prior to version 6.0.3, since version 4.0.0 contains a Directory Traversal vulnerability in The "Import Repository from Zip" feature, available through the Admin menu -> Import & Export -> Repositories, triggers a vuln...
CVE-2016-10036
- EPSS 13.5%
- Veröffentlicht 01.05.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 02:43:07
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary...
CVE-2016-6501
- EPSS 1.69%
- Veröffentlicht 09.12.2016 22:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.