vendor:
Artifactory
by:
Alessio Sergi
9.8
CVSS
CRITICAL
Unauthenticated Arbitrary File Upload / Remote Command Execution
22
CWE
Product Name: Artifactory
Affected Version From: < 4.16
Affected Version To: < 4.16
Patch Exists: YES
Related CWE: CVE-2016-10036
CPE: a:jfrog:artifactory
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Jfrog Artifactory < 4.16 - Unauthenticated Arbitrary File Upload / Remote Command Execution
Jfrog Artifactory < 4.16 is vulnerable to unauthenticated arbitrary file upload and directory traversal vulnerabilities. The vulnerabilities are within the upload api "/artifactory/ui/artifact/upload", require that "Allow Anonymous Access" is enabled (as it is on a default installation) and can be abused to create or overwrite files on the server. Specifically, it is possible to create or overwrite any files inside the application folder (scenario 1) or deploy a new application (scenario 2) and execute arbitrary code on the server.
Mitigation:
Disable "Allow Anonymous Access"