How to fix
Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.
Self Hosted EnvironmentsTo fix this issue, there is required action.
Upgrade your version of Artifactory or Edge to one of the versions listed below:
7.33.6 and above
6.23.38 and above
Workarounds and Mitigations
There aren’t any suggested workarounds to this issue besides upgrading to a fixed version.
CWE-352: Cross-Site Request Forgery (CSRF)
This issue was discovered and reported by Maxime Escourbiac and Maxence Schmitt at Michelin CERT.
We Are Here For Your Questions (JFrog Support Team)
If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.