CVE-2023-42509Improper Handling of Exceptional Conditions in Artifactory

Severity
7.5HIGHNVD
CNA6.6
EPSS
0.3%
top 48.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 7

Description

JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5jfrog/artifactory7.17.47.77.0
NVDjfrog/artifactory7.17.47.77.0

🔴Vulnerability Details

2
GHSA
GHSA-3ccw-6p8h-92ch: JFrog Artifactory later than version 72024-03-07
CVEList
JFrog Artifactory Sensitive Data Leakage in Repository configuration process2024-03-07
CVE-2023-42509 — Jfrog Artifactory vulnerability | cvebase