CVE-2024-4142

Published May 1, 2024

Last updated 4 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-4142 is an improper input validation vulnerability discovered in JFrog Artifactory. This flaw, categorized as CWE-20, allows for potential privilege escalation within the system. Due to this vulnerability, users with low privileges could gain administrative access. The issue can also be exploited in Artifactory platforms where anonymous access is enabled, expanding the potential attack surface. The vulnerability stems from the application's failure to properly validate user-supplied input before processing it in security-sensitive operations, enabling attackers to manipulate input to bypass authorization checks.

Description
An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.
Source
reefs@jfrog.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
9
Impact score
6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

reefs@jfrog.com
CWE-20

Social media

Hype score
Not currently trending