Risk Scores
EPSS Score
94.46%
100.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu | Ubuntu Linux | |
| JFrog | JFrog Artifactory | |
| Red Hat | Red Hat Enterprise Linux | |
| JFrog | JFrog Artifactory <7.46.3 | |
| SUSE | SUSE Linux |
Timeline
- Nov 23, 2017 PoC Published
- Mar 12, 2018 PoC Published
- Feb 5, 2019 PoC Published
- Sep 17, 2020 PoC Published
- Oct 3, 2020 PoC Published
- Mar 4, 2021 PoC Published
- Apr 26, 2021 PoC Published
- Jun 28, 2021 PoC Published
- Jul 2, 2021 PoC Published
- Sep 23, 2021 PoC Published
- Oct 6, 2021 PoC Published
- Dec 11, 2021 PoC Published
References
- https://wid.cert-bund.de/.well-known/csaf/white/2022/wid-sec-w-2022-1375.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-1375 advisory
- https://www.jfrog.com/confluence/display/JFROG/Fixed+Security+Vulnerabilities advisory
- https://access.redhat.com/errata/RHSA-2022:6782 advisory
- https://ubuntu.com/security/notices/USN-5776-1 advisory
- https://access.redhat.com/errata/RHSA-2023:5165 advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UB7MGNRMXC5LO5Y66FLOE354VVU5ULQK/ advisory
- Patch that Vuln! Identify, Triage, and Qualify CVEs third-party-analysis
- Spring: CVE-2022-22963 & Spring4Shell (CVE-2022-22965) | Fastly third-party-analysis