Jfrog Artifactory vulnerabilities

36 known vulnerabilities affecting jfrog/artifactory.

Total CVEs
36
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH11MEDIUM16LOW1

Vulnerabilities

Page 1 of 2
CVE-2025-14830MEDIUMCVSS 4.9≥ >=7.94.0, ≤ <7.117.102026-01-04
CVE-2025-14830 [MEDIUM] CWE-79 CVE-2025-14830: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artifactory (Workers) allows Cross-Site Scripting (XSS).This issue affects Artifactory (Workers): from >=7.94.0 through <7.117.10.
cvelistv5nvd
CVE-2024-6915CRITICALCVSS 9.3fixed in 7.90.6fixed in 7.84.20+6 more2024-08-05
CVE-2024-6915 [CRITICAL] CWE-20 CVE-2024-6915: JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55. JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.
cvelistv5nvd
CVE-2024-2248MEDIUMCVSS 6.4fixed in 7.85.0fixed in 7.84.72024-05-15
CVE-2024-2248 [MEDIUM] CWE-20 CVE-2024-2248: A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (S A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s user email.
cvelistv5nvd
CVE-2024-4142CRITICALCVSS 9.0fixed in 7.84.6fixed in 7.77.11+5 more2024-05-01
CVE-2024-4142 [CRITICAL] CWE-20 CVE-2024-4142: An Improper input validation vulnerability that could potentially lead to privilege escalation was d An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.
cvelistv5nvd
CVE-2024-3505MEDIUMCVSS 4.3fixed in 7.77.32024-04-15
CVE-2024-3505 [MEDIUM] CWE-200 CVE-2024-3505: JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclos JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.
nvd
CVE-2024-2247MEDIUMCVSS 6.1≤ 7.77.7fixed in 7.77.7+1 more2024-03-13
CVE-2024-2247 [MEDIUM] CWE-79 CVE-2024-2247: JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting du JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.
cvelistv5nvd
CVE-2023-42509HIGHCVSS 7.5≥ 7.17.4, < 7.77.02024-03-07
CVE-2023-42509 [HIGH] CWE-755 CVE-2023-42509: JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue wh JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.
cvelistv5nvd
CVE-2023-42661HIGHCVSS 8.8fixed in 7.76.22024-03-07
CVE-2023-42661 [HIGH] CWE-20 CVE-2023-42661: JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, w JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.
cvelistv5nvd
CVE-2023-42662MEDIUMCVSS 6.5≥ 7.59.0, < 7.59.18≥ 7.63.5, < 7.63.18+6 more2024-03-07
CVE-2023-42662 [MEDIUM] CWE-287 CVE-2023-42662: JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerabl JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.
cvelistv5nvd
CVE-2023-42508MEDIUMCVSS 6.5≥ 7.0.0, < 7.66.02023-10-03
CVE-2023-42508 [MEDIUM] CWE-20 CVE-2023-42508: JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body.
cvelistv5nvd
CVE-2022-0668CRITICALCVSS 9.8≥ 6.0.0, < 6.23.41≥ 7.0.0, < 7.37.132023-01-08
CVE-2022-0668 [CRITICAL] CWE-274 CVE-2022-0668: JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privile JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.
nvd
CVE-2021-23163HIGHCVSS 8.8≥ 6.0.0, < 6.23.38≥ 7.0.0, < 7.33.62022-07-06
CVE-2021-23163 [HIGH] CWE-352 CVE-2021-23163: JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Fo JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
nvd
CVE-2021-46687MEDIUMCVSS 4.9≥ 6.0.0, < 6.23.38≥ 7.0.0, < 7.31.102022-07-06
CVE-2021-46687 [MEDIUM] CWE-359 CVE-2021-46687: JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure thro JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
nvd
CVE-2021-45721MEDIUMCVSS 6.1≥ 6.0.0, < 6.23.38≥ 7.0.0, < 7.29.82022-07-06
CVE-2021-45721 [MEDIUM] CWE-79 CVE-2021-45721: JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scriptin JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before 6.23.41 versions prior to 6.23.38.
nvd
CVE-2021-41834MEDIUMCVSS 6.5fixed in 6.23.38≥ 7.0.0, < 7.28.0+2 more2022-05-23
CVE-2021-41834 [MEDIUM] CWE-284 CVE-2021-41834: JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the c JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.
cvelistv5nvd
CVE-2021-45730MEDIUMCVSS 4.9≥ 7.0.0, < 7.31.10≥ 7.x, < 7.31.102022-05-19
CVE-2021-45730 [MEDIUM] CWE-284 CVE-2021-45730: JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.
cvelistv5nvd
CVE-2022-0573HIGHCVSS 8.8≥ 6.0.0, < 6.23.41≥ 7.0.0, < 7.17.16+11 more2022-05-16
CVE-2022-0573 [HIGH] CWE-502 CVE-2022-0573: JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized object.
nvd
CVE-2021-45074MEDIUMCVSS 5.4≥ 6.0.0, < 6.23.38≥ 7.0.0, < 7.29.32022-03-02
CVE-2021-45074 [MEDIUM] CWE-284 CVE-2021-45074: JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privilege JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.
nvd
CVE-2021-46270LOWCVSS 2.7≥ 7.0.0, < 7.31.102022-03-02
CVE-2021-46270 [LOW] CWE-284 CVE-2021-46270: JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.
nvd
CVE-2021-3860HIGHCVSS 8.8fixed in 6.23.30≥ 7.11.0, < 7.11.8+8 more2021-12-20
CVE-2021-3860 [HIGH] CWE-89 CVE-2021-3860: JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.
nvd