Description
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.
Remediation
References
Related Vulnerabilities
WordPress Plugin Comments-wpDiscuz Cross-Site Request Forgery (7.3.3)
Drupal Improper Authentication Vulnerability (CVE-2006-1228)
MySQL CVE-2015-0374 Vulnerability (CVE-2015-0374)
MySQL CVE-2016-0599 Vulnerability (CVE-2016-0599)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-1501)