CVE Vulnerabilities

CVE-2020-7931

Published: Jan 23, 2020 | Modified: Jan 30, 2020
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the DefaultObjectWrapper class makes certain Java functions accessible to a template.

Affected Software

Name Vendor Start Version End Version
Artifactory Jfrog * 5.11.8 (excluding)
Artifactory Jfrog 6.0.0 (including) 6.1.6 (excluding)
Artifactory Jfrog 6.2.0 (including) 6.3.9 (excluding)
Artifactory Jfrog 6.4.0 (including) 6.7.8 (excluding)
Artifactory Jfrog 6.8.0 (including) 6.8.17 (excluding)
Artifactory Jfrog 6.9.0 (including) 6.9.6 (excluding)
Artifactory Jfrog 6.10.0 (including) 6.10.9 (excluding)
Artifactory Jfrog 6.11.0 (including) 6.11.7 (excluding)
Artifactory Jfrog 6.12.0 (including) 6.12.3 (excluding)
Artifactory Jfrog 6.13.0 (including) 6.13.2 (excluding)
Artifactory Jfrog 6.14.0 (including) 6.14.2 (excluding)
Artifactory Jfrog 6.15.0 (including) 6.15.1 (excluding)

References