| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Credentials for a deleted user may remain valid for a short period under specific conditions. |
| An unauthenticated user may access restricted repository information under specific conditions. |
| An authenticated user without repository read permission may access private NuGet metadata under specific conditions. |
| An authenticated user may view private Puppet module metadata without repository read access. |
| An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. |
| A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. |
| An authenticated user may write files outside the intended Artifactory work directory under specific conditions. |
| A Project Resource Manager may gain broader administrative privileges under specific conditions. |
| An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. |
| A repository publisher without delete permission may modify protected package content under specific conditions. |
| A bundle writer may create misleading release promotion information under specific conditions. |
| A party with write access to stored session data may affect JFrog Artifactory under specific conditions. |
| A user with access to a valid SAML response may impersonate another user under specific conditions. |
| An unauthenticated user may bypass authentication under specific cache conditions. |
| A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution. |
| A low-privileged authenticated user may access restricted support information under specific conditions. |
| A holder of a valid integration credential may impersonate other users under specific conditions. |
| GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation. |
| Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation. |
| A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. |