logo

299 Authentication mechanism absence or evasion - JFROG


Description

The application functions are accessed without the need to be logged into the server.


Impact

- Access Artifactory repositories. - Upload files to any repository without authorization. - Delete files from any repository without authentication.


Recommendation

Protect resources that are not authenticated for access.


Threat

Anonymous attacker from intranet.


Expected Remediation Time

60 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: A
  • Attack complexity: L
  • Attack Requirements: N
  • Privileges required: L
  • User interaction: N
  • Confidentiality (VC): H
  • Integrity (VI): N
  • Availability (VA): N
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: X

Requirements


Last updated

2024/02/19