CVE-2024-2247

CVSS 3.1 Score 10.0 of 10 (high)

Details

Published Mar 13, 2024
Updated: Mar 14, 2024
CWE ID 20

Summary

CVE-2024-2247 is a newly disclosed vulnerability affecting JFrog Artifactory versions prior to 7.77.7 and 7.82.1. This issue stems from the improper handling of the import override mechanism, which opens the door to DOM-based cross-site scripting attacks. An attacker can exploit this vulnerability by tricking a user into accessing a specially crafted web page, allowing the adversary to inject malicious scripts into the victim's browser session. The potential consequences range from information disclosure to complete session takeover. Users are strongly advised to upgrade their JFrog Artifactory instances to the patched versions as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-2247 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions