BIT-artifactory-2020-7931

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/artifactory/BIT-artifactory-2020-7931.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-artifactory-2020-7931
Aliases
  • CVE-2020-7931
Published
2024-03-06T10:52:43.400Z
Modified
2025-04-03T14:40:37.652Z
Summary
[none]
Details

In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the DefaultObjectWrapper class makes certain Java functions accessible to a template.

Database specific
{
    "cpes": [
        "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / artifactory

Package

Name
artifactory
Purl
pkg:bitnami/artifactory

Severity

  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.11.8
Introduced
6.0.0
Fixed
6.1.6
Introduced
6.2.0
Fixed
6.3.9
Introduced
6.4.0
Fixed
6.7.8
Introduced
6.8.0
Fixed
6.8.17
Introduced
6.9.0
Fixed
6.9.6
Introduced
6.10.0
Fixed
6.10.9
Introduced
6.11.0
Fixed
6.11.7
Introduced
6.12.0
Fixed
6.12.3
Introduced
6.13.0
Fixed
6.13.2
Introduced
6.14.0
Fixed
6.14.2
Introduced
6.15.0
Fixed
6.15.1