CVE-2023-42662

JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.
Configurations

No configuration.

History

21 Nov 2024, 08:22

Type Values Removed Values Added
Summary
  • (es) Las versiones de JFrog Artifactory 7.59 y superiores, pero inferiores a 7.59.18, 7.63.18, 7.68.19, 7.71.8 son vulnerables a un problema por el cual la interacción del usuario con URL especialmente manipuladas podría provocar la exposición de los tokens de acceso del usuario debido a un manejo inadecuado del Integración SSO basada en navegador CLI/IDE.
References () https://jfrog.com/help/r/jfrog-release-information/jfrog-security-advisories - () https://jfrog.com/help/r/jfrog-release-information/jfrog-security-advisories -

07 Mar 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-07 09:15

Updated : 2024-11-21 08:22


NVD link : CVE-2023-42662

Mitre link : CVE-2023-42662

CVE.ORG link : CVE-2023-42662


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication