CVE-2023-42661

JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.
Configurations

No configuration.

History

21 Nov 2024, 08:22

Type Values Removed Values Added
References () https://jfrog.com/help/r/jfrog-release-information/jfrog-security-advisories - () https://jfrog.com/help/r/jfrog-release-information/jfrog-security-advisories -

08 Mar 2024, 14:02

Type Values Removed Values Added
Summary
  • (es) JFrog Artifactory anterior a la versión 7.76.2 es vulnerable a la escritura arbitraria de archivos de datos que no son de confianza, lo que puede provocar DoS o ejecución remota de código cuando un usuario autenticado envía una serie de solicitudes especialmente manipuladas. Esto se debe a una validación insuficiente de los artefactos.

07 Mar 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-07 14:15

Updated : 2024-11-21 08:22


NVD link : CVE-2023-42661

Mitre link : CVE-2023-42661

CVE.ORG link : CVE-2023-42661


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation