CVE-2021-45721

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
06/07/2022
Last modified:
13/07/2022

Description

JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before 6.23.41 versions prior to 6.23.38.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:* 6.0.0 (including) 6.23.38 (excluding)
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:* 7.0.0 (including) 7.29.8 (excluding)