HIGH
JFrog JFrog Artifactory version Prior to version 6.0.3, since version 4.0.0 contains a Directory Traversal vulnerability in The "Import Repository from Zip" feature, available through the Admin menu -> Import & Export -> Repositories, triggers a vulnerable UI REST endpoint (/ui/artifactimport/upload) that can result in Directory traversal / file overwrite and remote code execution
Published Jul 9, 2018
7.2
HIGHCVSS 3.0
EPSS 2.82%
Description
Affected products
Remediation
References (1)
Change history (0)
No recorded changes yet.