CVE-2024-2247
CVSS 3.1 Score 10.0 of 10 (high)
Details
Summary
CVE-2024-2247 is a newly disclosed vulnerability affecting JFrog Artifactory versions prior to 7.77.7 and 7.82.1. This issue stems from the improper handling of the import override mechanism, which opens the door to DOM-based cross-site scripting attacks. An attacker can exploit this vulnerability by tricking a user into accessing a specially crafted web page, allowing the adversary to inject malicious scripts into the victim's browser session. The potential consequences range from information disclosure to complete session takeover. Users are strongly advised to upgrade their JFrog Artifactory instances to the patched versions as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.