Description
JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized object.
Remediation
References
Related Vulnerabilities
MySQL CVE-2017-3452 Vulnerability (CVE-2017-3452)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-5270)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3546)
MyBB Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-4629)
OpenSSL Improper Authentication Vulnerability (CVE-2009-0653)