Description
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2019-2964 Vulnerability (CVE-2019-2964)
WordPress Plugin Templatic Tevolution Arbitrary File Upload (2.3.6)
MySQL CVE-2024-20967 Vulnerability (CVE-2024-20967)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17307)
WordPress Plugin Starbox-the Author Box for Humans Cross-Site Scripting (3.0.8)