CVE-2021-23163

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
06/07/2022
Last modified:
13/07/2022

Description

JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:* 6.0.0 (including) 6.23.38 (excluding)
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:* 7.0.0 (including) 7.33.6 (excluding)