CVE-2021-3860 is a Blind SQL Injection vulnerability affecting JFrog Artifactory Enterprise+ deployments prior to version 7.25.4. A low-privileged authenticated user can exploit this flaw due to insufficient input validation during SQL query execution. This vulnerability carries a high CVSS score of 8.8, indicating a network-based attack with low complexity, requiring only low privileges, and leading to high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.23.30CPE matchmatch criteria | cpe:2.3:a:jfrog:artifactory:*:*:*:*:enterprise\+:*:*:* | ||
>= 7.11.0, < 7.11.8CPE matchmatch criteria | cpe:2.3:a:jfrog:artifactory:*:*:*:*:enterprise\+:*:*:* | ||
>= 7.12.0, < 7.12.10CPE matchmatch criteria | cpe:2.3:a:jfrog:artifactory:*:*:*:*:enterprise\+:*:*:* | ||
>= 7.17.0, < 7.17.14CPE matchmatch criteria | cpe:2.3:a:jfrog:artifactory:*:*:*:*:enterprise\+:*:*:* | ||
>= 7.18.0, < 7.18.11CPE matchmatch criteria | cpe:2.3:a:jfrog:artifactory:*:*:*:*:enterprise\+:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Artifactory Low Privileged Blind SQL Injection
Dec 15, 2021JFrog Artifactory prior to version 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.
Dec 15, 2021JFrog Security Advisories