CVE-2016-10036
Jfrog Artifactory < 4.16 - Arbitrary File Upload / Remote Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.
Vulnerabilidad de subida de archivos sin restricción en ui/artifact/upload en JFrog Artifactory, en versiones anteriores a la 4.16, permite que atacantes remotos (1) desplieguen una aplicación del servlet arbitraria y ejecuten código arbitrario mediante la subida de un archivo war o (2) puedan escribir en archivos arbitrarios y provoquen una denegación de servicio (DoS) mediante la subida de un archivo HTML.
Jfrog Artifactory versions prior to 4.16 suffer from unauthenticated arbitrary file upload and remote command execution vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-23 CVE Reserved
- 2018-04-26 CVE Published
- 2018-04-26 First Exploit
- 2024-08-06 CVE Updated
- 2025-01-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/147378 | 2018-04-26 | |
https://www.exploit-db.com/exploits/44543 | 2024-08-06 | |
http://packetstormsecurity.com/files/147378/Jfrog-Artifactory-Code-Execution-Shell-Upload.html | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.jfrog.com/confluence/display/RTF/Release+Notes#ReleaseNotes-Artifactory4.16 | 2018-06-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jfrog Search vendor "Jfrog" | Artifactory Search vendor "Jfrog" for product "Artifactory" | < 4.16 Search vendor "Jfrog" for product "Artifactory" and version " < 4.16" | - |
Affected
|