Home » Database

AVID-2026-R0929

Description

Vulnerability CVE-2021-45074

Details

JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.

Reason for inclusion in AVID: CVE-2021-45074 describes a broken access control vulnerability in JFrog Artifactory affecting OAuth tokens; Artifactory is a widely-used artifact/repository tool in software supply chains and ML pipelines, so this is a software supply chain vulnerability relevant to general-purpose AI systems; it is a security vulnerability with clear evidence (CVE entry, CVSS details, references).

References

Affected or Relevant Artifacts

  • Developer: JFrog
  • Deployer: JFrog
  • Artifact Details:
TypeName
SystemJFrog Artifactory

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Base Score4.3
Base Severity🟠 Medium
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges Required🟢 Low
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability Impact🟢 Low

CWE

IDDescription
CWE-284CWE-284 Improper Access Control

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2022-03-02
  • Version: 0.3.3
  • AVID Entry