CVE-2023-42662

CRITICAL

JFrog Artifactory 7.59.0-7.59.17 - Unauthenticated Access Token Exposure via CLI/IDE Browser SSO Integration

Title source: llm
STIX 2.1

Description

JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.

References (1)

Core 1

Scores

CVSS v3 9.3
EPSS 0.0047
EPSS Percentile 37.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
jfrog/artifactory 7.59.0 - 7.59.18
Published Mar 07, 2024
Tracked Since Feb 18, 2026