CVE-2024-6915 is a critical improper input validation vulnerability affecting JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, and 7.55.18. With a CVSS score of 9.3, this network-exploitable flaw requires no user interaction and could lead to cache poisoning with high integrity and low availability impacts. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 7.55.18CPE match | cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:*:*:* | ||
>= 0, < 7.59.23CPE match | cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:*:*:* | ||
>= 0, < 7.63.22CPE match | cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:*:*:* | ||
>= 0, < 7.68.22CPE match | cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:*:*:* | ||
>= 0, < 7.71.23CPE match | cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cache Poisoning
Aug 5, 2024JFrog Artifactory is vulnerable to Improper Input Validation that could potentially lead to Cache Poisoning.
Aug 5, 2024JFrog Security Advisories