Jfrog Artifactory vulnerabilities
79 known vulnerabilities affecting jfrog/artifactory.
Total CVEs
79
CISA KEV
2
actively exploited
Public exploits
4
Exploited in wild
5
Severity breakdown
CRITICAL10HIGH26MEDIUM40LOW3
Vulnerabilities
Page 2 of 4
CVE-2018-19971P3CRITICALCVSS 9.8v6.5.92019-04-16
CVE-2018-19971 [CRITICAL] CWE-345 CVE-2018-19971: JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.
JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.
nvd
CVE-2024-6915P3CRITICALCVSS 9.3fixed in 7.90.6fixed in 7.84.20+6 more2024-08-05
CVE-2024-6915 [CRITICAL] CWE-20 CVE-2024-6915: JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.
JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.
nvd
CVE-2021-3860P3HIGHCVSS 8.8fixed in 6.23.30≥ 7.11.0, < 7.11.8+8 more2021-12-20
CVE-2021-3860 [HIGH] CWE-89 CVE-2021-3860: JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection
JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.
nvd
CVE-2026-68757P3HIGHCVSS 7.5fixed in 7.146.35≥ 7.161.0, < 7.161.162026-08-12
CVE-2026-68757 [HIGH] CWE-347 CVE-2026-68757: A user with access to a valid SAML response may impersonate another user under specific conditions.
A user with access to a valid SAML response may impersonate another user under specific conditions.
nvd
CVE-2026-68752P3HIGHCVSS 7.2fixed in 7.146.352026-08-12
CVE-2026-68752 [HIGH] CWE-269 CVE-2026-68752: A Project Resource Manager may gain broader administrative privileges under specific conditions.
A Project Resource Manager may gain broader administrative privileges under specific conditions.
nvd
CVE-2026-66015P3HIGHCVSS 7.2≥ 7.146.0, < 7.146.34≥ 7.161.0, < 7.161.152026-07-27
CVE-2026-66015 [HIGH] CWE-269 CVE-2026-66015: An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-p
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.
nvd
CVE-2026-66375P3HIGHCVSS 8.1fixed in 7.146.35≥ 7.161.0, < 7.161.162026-08-12
CVE-2026-66375 [HIGH] CWE-862 CVE-2026-66375: A low-privilege authenticated user may permanently remove protected internal metadata across reposit
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
nvd
CVE-2026-65923P3MEDIUMCVSS 6.8fixed in 7.111.18≥ 7.117.0, < 7.117.25+4 more2026-07-27
CVE-2026-65923 [MEDIUM] CWE-918 CVE-2026-65923: A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests.
The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.
nvd
CVE-2018-1000623P3HIGHCVSS 7.2≥ 4.0.0, < 6.0.32018-07-09
CVE-2018-1000623 [HIGH] CWE-22 CVE-2018-1000623: JFrog JFrog Artifactory version Prior to version 6.0.3, since version 4.0.0 contains a Directory Tra
JFrog JFrog Artifactory version Prior to version 6.0.3, since version 4.0.0 contains a Directory Traversal vulnerability in The "Import Repository from Zip" feature, available through the Admin menu -> Import & Export -> Repositories, triggers a vulnerable UI REST endpoint (/ui/artifactimport/upload) that can result in Directory traversal / file ov
nvd
CVE-2026-69105P3HIGHCVSS 8.1≥ 7.161.0, < 7.161.162026-08-12
CVE-2026-69105 [HIGH] CWE-345 CVE-2026-69105: An unauthenticated attacker may cause untrusted package content to be cached under specific conditio
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
nvd
CVE-2026-65924P3MEDIUMCVSS 6.5fixed in 7.111.18≥ 7.117.0, < 7.117.25+4 more2026-07-27
CVE-2026-65924 [MEDIUM] CWE-918 CVE-2026-65924: JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Si
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.
nvd
CVE-2021-23163P3HIGHCVSS 8.8≥ 6.0.0, < 6.23.38≥ 7.0.0, < 7.33.62022-07-06
CVE-2021-23163 [HIGH] CWE-352 CVE-2021-23163: JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Fo
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
nvd
CVE-2026-65925P3MEDIUMCVSS 6.5fixed in 7.111.18≥ 7.117.0, < 7.117.25+4 more2026-07-27
CVE-2026-65925 [MEDIUM] CWE-918 CVE-2026-65925: A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request uni
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
nvd
CVE-2026-69104P3HIGHCVSS 7.6≥ 7.161.0, < 7.161.192026-08-25
CVE-2026-69104 [HIGH] CWE-862 CVE-2026-69104: An authenticated user may initiate repository migration operations without required repository permi
An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.
nvd
CVE-2026-68759P3HIGHCVSS 7.2fixed in 7.146.35≥ 7.161.0, < 7.161.162026-08-12
CVE-2026-68759 [HIGH] CWE-347 CVE-2026-68759: A holder of a valid integration credential may impersonate other users under specific conditions.
A holder of a valid integration credential may impersonate other users under specific conditions.
nvd
CVE-2023-42509P3HIGHCVSS 7.5≥ 7.17.4, < 7.77.02024-03-07
CVE-2023-42509 [HIGH] CWE-755 CVE-2023-42509: JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue wh
JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.
nvd
CVE-2026-65618P3MEDIUMCVSS 6.5fixed in 7.133.62026-07-27
CVE-2026-65618 [MEDIUM] CWE-918 CVE-2026-65618: Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, t
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
nvd
CVE-2026-66018P3MEDIUMCVSS 6.5≥ 7.146.0, < 7.146.34≥ 7.161.0, < 7.161.152026-07-27
CVE-2026-66018 [MEDIUM] CWE-200 CVE-2026-66018: Build readers can access another repository's environment properties. A caller with read access to a
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
nvd
CVE-2026-70550P3MEDIUMCVSS 6.5≥ 7.161.0, < 7.161.19≥ 7.146.0, < 7.146.292026-08-25
CVE-2026-70550 [MEDIUM] CWE-862 CVE-2026-70550: An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticat
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.
nvd
CVE-2020-2165P3HIGHCVSS 7.5≤ 3.6.02020-03-25
CVE-2020-2165 [HIGH] CWE-522 CVE-2020-2165: Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of
Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
nvd