CVE-2023-42662
Estado: AnalizadaMedia (6.5)—
JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.47%
- Percentil entre todas las CVEs puntuadas: 39
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-42662",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-42662",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-08-02T19:58:18.611412Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "reefs@jfrog.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.3,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.8,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "reefs@jfrog.com",
"affectedData": [
{
"vendor": "JFrog",
"product": "Artifactory",
"versions": [
{
"status": "affected",
"version": "7.59",
"lessThan": "7.59.18",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.59",
"lessThan": "7.63.18",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.59",
"lessThan": "7.68.19",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.59",
"lessThan": "7.71.8",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:*:*:*"
],
"vendor": "jfrog",
"product": "artifactory",
"versions": [
{
"status": "affected",
"version": "7.59",
"lessThan": "7.59.18",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.59",
"lessThan": "7.63.18",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.59",
"lessThan": "7.68.19",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.59",
"lessThan": "7.71.8",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-03-07T09:15:38.290",
"references": [
{
"url": "https://jfrog.com/help/r/jfrog-release-information/jfrog-security-advisories",
"tags": [
"Vendor Advisory"
],
"source": "reefs@jfrog.com"
},
{
"url": "https://jfrog.com/help/r/jfrog-release-information/jfrog-security-advisories",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "reefs@jfrog.com",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.\n"
},
{
"lang": "es",
"value": "Las versiones de JFrog Artifactory 7.59 y superiores, pero inferiores a 7.59.18, 7.63.18, 7.68.19, 7.71.8 son vulnerables a un problema por el cual la interacción del usuario con URL especialmente manipuladas podría provocar la exposición de los tokens de acceso del usuario debido a un manejo inadecuado del Integración SSO basada en navegador CLI/IDE."
}
],
"lastModified": "2026-06-17T06:24:12.560",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"vulnerable": true,
"matchCriteriaId": "C24F3D9E-9364-4570-96ED-433AFFE5144C",
"versionEndExcluding": "7.59.18",
"versionStartIncluding": "7.59.0"
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"vulnerable": true,
"matchCriteriaId": "A8B53DA3-129E-4030-AAEA-13DE15E2D99C",
"versionEndExcluding": "7.63.18",
"versionStartIncluding": "7.63.5"
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"vulnerable": true,
"matchCriteriaId": "17B54888-01AA-45AC-BCA6-2AECBFE28CE2",
"versionEndExcluding": "7.68.19",
"versionStartIncluding": "7.68.7"
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"vulnerable": true,
"matchCriteriaId": "D8B7666E-8012-403A-8D42-75BD4D82F16E",
"versionEndExcluding": "7.71.8",
"versionStartIncluding": "7.71.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "reefs@jfrog.com"
}