CVE-2021-3860

JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
JFROGCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
VendorProductVersion
jfrogartifactory
𝑥
< 6.23.30
jfrogartifactory
7.11.0 ≤
𝑥
< 7.11.8
jfrogartifactory
7.12.0 ≤
𝑥
< 7.12.10
jfrogartifactory
7.17.0 ≤
𝑥
< 7.17.14
jfrogartifactory
7.18.0 ≤
𝑥
< 7.18.11
jfrogartifactory
7.19.0 ≤
𝑥
< 7.19.12
jfrogartifactory
7.21.0 ≤
𝑥
< 7.21.14
jfrogartifactory
7.23.0 ≤
𝑥
< 7.23.8
jfrogartifactory
7.24.0 ≤
𝑥
< 7.24.7
jfrogartifactory
7.25.0 ≤
𝑥
< 7.25.4
𝑥
= Vulnerable software versions