VYPR
Unrated severityNVD Advisory· Published Dec 20, 2021· Updated Nov 18, 2024

CVE-2021-3860

CVE-2021-3860

Description

JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.

Affected products

2
  • osv-coords
    Range: < 6.23.30
  • JFrog/JFrog Artifactoryv5
    Range: JFrog Artifactory versions before 7.25.4 with E+ license

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.