In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.secureworks.com/research/subject/advisories | third party advisory |
https://www.jfrog.com/confluence/display/RTF6X/Release+Notes#ReleaseNotes-Artifactory6.18 | release notes |
https://www.jfrog.com/confluence/display/RTF6X/Importing+and+Exporting | vendor advisory |