
Cloud Vulnerability DB
A community-led vulnerabilities database
A Header Injection vulnerability (CVE-2024-2248) was identified in the JFrog platform affecting versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted). The vulnerability was disclosed on May 15, 2024, and is classified as a medium severity issue with a CVSS v3.1 base score of 6.4 (NVD).
The vulnerability is categorized as CWE-20 (Improper Input Validation) and requires user interaction to exploit. The vulnerability has been assigned a CVSS vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H, indicating network accessibility, high attack complexity, no privileges required, and user interaction required (NVD).
If successfully exploited, this vulnerability could allow threat actors to take over the end user's account when the victim clicks on a specially crafted URL sent to their email (NVD).
Users are advised to upgrade their JFrog platform installations to version 7.85.0 or later for SaaS deployments, or version 7.84.7 or later for Self-Hosted installations (JFrog Advisories).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."