AI description
Automated description summarized from trusted sources.
CVE-2024-4142 is an improper input validation vulnerability discovered in JFrog Artifactory. This flaw, categorized as CWE-20, allows for potential privilege escalation within the system. Due to this vulnerability, users with low privileges could gain administrative access. The issue can also be exploited in Artifactory platforms where anonymous access is enabled, expanding the potential attack surface. The vulnerability stems from the application's failure to properly validate user-supplied input before processing it in security-sensitive operations, enabling attackers to manipulate input to bypass authorization checks.
- Description
- An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.
- Source
- reefs@jfrog.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 9
- Impact score
- 6
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- reefs@jfrog.com
- CWE-20
- Hype score
- Not currently trending