299 – Authentication mechanism absence or evasion - JFROG
Description
The application functions are accessed without the need to be logged into the server.
Impact
- Access Artifactory repositories. - Upload files to any repository without authorization. - Delete files from any repository without authentication.
Recommendation
Protect resources that are not authenticated for access.
Threat
Anonymous attacker from intranet.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: A
- Attack complexity: L
- Attack Requirements: N
- Privileges required: L
- User interaction: N
- Confidentiality (VC): H
- Integrity (VI): N
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: X