CVE-2018-1000206

Source
https://cve.org/CVERecord?id=CVE-2018-1000206
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000206.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-1000206
Published
2018-07-13T18:29:00.210Z
Modified
2026-04-10T04:03:23.557574Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF attack allowing an attacker to perform actions as logged in user. This attack appear to be exploitable via The victim must run maliciously crafted flash component. This vulnerability appears to have been fixed in 6.1.

References

Affected packages

Git / github.com/jfrog/artifactory-docker-examples

Affected ranges

Type
GIT
Repo
https://github.com/jfrog/artifactory-docker-examples
Events
Database specific
{
    "versions": [
        {
            "introduced": "5.11.0"
        },
        {
            "fixed": "6.1.0"
        }
    ]
}

Affected versions

5.*
5.11.0
6.*
6.0.1
6.0.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000206.json"