Jfrog Artifactory vulnerabilities
79 known vulnerabilities affecting jfrog/artifactory.
Total CVEs
79
CISA KEV
2
actively exploited
Public exploits
4
Exploited in wild
5
Severity breakdown
CRITICAL10HIGH26MEDIUM40LOW3
Vulnerabilities
Page 3 of 4
CVE-2019-19937P3HIGHCVSS 7.2fixed in 6.182020-03-16
CVE-2019-19937 [HIGH] CWE-862 CVE-2019-19937: In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports
In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."
nvd
CVE-2018-1000206P3HIGHCVSS 8.8≥ 5.11.0, < 6.1.02018-07-13
CVE-2018-1000206 [HIGH] CWE-352 CVE-2018-1000206: JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI
JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF attack allowing an attacker to perform actions as logged in user. This attack appear to be exploitable via The victim must run maliciously crafted flash component. This vulnerability appears to have be
nvd
CVE-2026-68758P3MEDIUMCVSS 6.5fixed in 7.146.35≥ 7.161.0, < 7.161.162026-08-12
CVE-2026-68758 [MEDIUM] CWE-862 CVE-2026-68758: A low-privileged authenticated user may access restricted support information under specific conditi
A low-privileged authenticated user may access restricted support information under specific conditions.
nvd
CVE-2018-1000424P3HIGHCVSS 7.8≤ 2.16.12019-01-09
CVE-2018-1000424 [HIGH] CWE-522 CVE-2018-1000424: An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 an
An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin.
nvd
CVE-2026-69107P3MEDIUMCVSS 5.9fixed in 7.104.16≥ 7.111.0, < 7.111.14+4 more2026-08-12
CVE-2026-69107 [MEDIUM] CWE-862 CVE-2026-69107: An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditio
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
nvd
CVE-2026-68760P3MEDIUMCVSS 5.3fixed in 7.146.35≥ 7.161.0, < 7.161.162026-08-12
CVE-2026-68760 [MEDIUM] CWE-287 CVE-2026-68760: An unauthenticated user may bypass authentication under specific cache conditions.
An unauthenticated user may bypass authentication under specific cache conditions.
nvd
CVE-2026-68756P3MEDIUMCVSS 6.6fixed in 7.146.35≥ 7.161.0, < 7.161.162026-08-12
CVE-2026-68756 [MEDIUM] CWE-502 CVE-2026-68756: A party with write access to stored session data may affect JFrog Artifactory under specific conditi
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
nvd
CVE-2021-41834P3MEDIUMCVSS 6.5fixed in 6.23.38≥ 7.0.0, < 7.28.0+2 more2022-05-23
CVE-2021-41834 [MEDIUM] CWE-284 CVE-2021-41834: JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the c
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.
nvd
CVE-2026-68754P3MEDIUMCVSS 6.5fixed in 7.146.35≥ 7.161.0, < 7.161.162026-08-12
CVE-2026-68754 [MEDIUM] CWE-862 CVE-2026-68754: A repository publisher without delete permission may modify protected package content under specific
A repository publisher without delete permission may modify protected package content under specific conditions.
nvd
CVE-2026-68753P3MEDIUMCVSS 5.3fixed in 7.146.35≥ 7.161.0, < 7.161.162026-08-12
CVE-2026-68753 [MEDIUM] CWE-862 CVE-2026-68753: An unauthenticated user may access restricted Artifactory content when a credentialed remote reposit
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
nvd
CVE-2020-2164P4MEDIUMCVSS 6.5≤ 3.5.02020-03-25
CVE-2020-2164 [MEDIUM] CWE-522 CVE-2020-2164: Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in i
Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
nvd
CVE-2023-42662P4MEDIUMCVSS 6.5≥ 7.59.0, < 7.59.18≥ 7.63.5, < 7.63.18+6 more2024-03-07
CVE-2023-42662 [MEDIUM] CWE-287 CVE-2023-42662: JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerabl
JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.
nvd
CVE-2023-42508P4MEDIUMCVSS 6.5≥ 7.0.0, < 7.66.02023-10-03
CVE-2023-42508 [MEDIUM] CWE-20 CVE-2023-42508: JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially
JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body.
nvd
CVE-2024-2248P4MEDIUMCVSS 6.4fixed in 7.85.0fixed in 7.84.72024-05-15
CVE-2024-2248 [MEDIUM] CWE-20 CVE-2024-2248: A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (S
A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s user email.
nvd
CVE-2026-65922P4MEDIUMCVSS 5.4fixed in 7.111.18≥ 7.117.0, < 7.117.25+4 more2026-07-27
CVE-2026-65922 [MEDIUM] CWE-862 CVE-2026-65922: An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with li
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.
nvd
CVE-2026-66381P4MEDIUMCVSS 5.3fixed in 7.146.35≥ 7.161.0, < 7.161.162026-08-12
CVE-2026-66381 [MEDIUM] CWE-22 CVE-2026-66381: A repository reader with cache-deploy permission may access content outside a configured upstream pa
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
nvd
CVE-2026-66377P4MEDIUMCVSS 5.3fixed in 7.146.35≥ 7.161.0, < 7.161.162026-08-12
CVE-2026-66377 [MEDIUM] CWE-862 CVE-2026-66377: An unauthenticated user may access restricted repository information under specific conditions.
An unauthenticated user may access restricted repository information under specific conditions.
nvd
CVE-2026-66376P4MEDIUMCVSS 5.4fixed in 7.146.35≥ 7.161.0, < 7.161.162026-08-12
CVE-2026-66376 [MEDIUM] CWE-613 CVE-2026-66376: Credentials for a deleted user may remain valid for a short period under specific conditions.
Credentials for a deleted user may remain valid for a short period under specific conditions.
nvd
CVE-2019-10324P4MEDIUMCVSS 6.5≤ 3.2.22019-05-31
CVE-2019-10324 [MEDIUM] CWE-352 CVE-2019-10324: A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in Releas
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven projects, and promote previously st
nvd
CVE-2026-66016P4MEDIUMCVSS 6.7fixed in 7.146.35≥ 7.161.0, < 7.161.162026-08-12
CVE-2026-66016 [MEDIUM] CWE-312 CVE-2026-66016: Under specific self-hosted Helm configurations, generated TLS private keys may be retained in render
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
nvd