CVE-2018-1000206 Information
Feb 14, 2021
cve
Description
JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF attack allowing an attacker to perform actions as logged in user. This attack appear to be exploitable via The victim must run maliciously crafted flash component. This vulnerability appears to have been fixed in 6.1.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://www.geekboy.ninja/blog/exploiting-json-cross-site-request-forgery-csrf-using-flash/ https://www.jfrog.com/jira/browse/RTFACT-17004 https://www.jfrog.com/jira/secure/ReleaseNote.jspa?projectId=10070&version=19581
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: