Jfrog Artifactory vulnerabilities
8 known vulnerabilities affecting jfrog/jfrog_artifactory.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM3LOW1
Vulnerabilities
Page 1 of 1
CVE-2022-0668CRITICALCVSS 9.8≥ JFrog Artifactory versions before 7.x, < 7.37.13≥ JFrog Artifactory versions before 6.x, < 6.23.412023-01-08
CVE-2022-0668 [CRITICAL] CWE-274 CVE-2022-0668: JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privile
JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.
cvelistv5nvd
CVE-2021-23163HIGHCVSS 8.8≥ JFrog Artifactory versions before 7.33.6, < 7.x≥ JFrog Artifactory versions before 6.23.38, < 6.x2022-07-06
CVE-2021-23163 [HIGH] CWE-352 CVE-2021-23163: JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Fo
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
cvelistv5nvd
CVE-2021-46687MEDIUMCVSS 4.9≥ JFrog Artifactory versions before 7.31.10, < 7.x≥ JFrog Artifactory versions before 6.23.38, < 6.x2022-07-06
CVE-2021-46687 [MEDIUM] CWE-359 CVE-2021-46687: JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure thro
JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
cvelistv5nvd
CVE-2021-45721MEDIUMCVSS 6.1≥ JFrog Artifactory versions before 7.36.1, < 7.29.8≥ JFrog Artifactory versions before 6.23.41, < 6.23.382022-07-06
CVE-2021-45721 [MEDIUM] CWE-79 CVE-2021-45721: JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scriptin
JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before 6.23.41 versions prior to 6.23.38.
cvelistv5nvd
CVE-2022-0573HIGHCVSS 8.8≥ JFrog Artifactory versions before 7.36.1, < 7.36.1≥ JFrog Artifactory versions before 6.23.41, < 6.23.412022-05-16
CVE-2022-0573 [HIGH] CWE-502 CVE-2022-0573: JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted
JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized object.
cvelistv5nvd
CVE-2021-45074MEDIUMCVSS 5.4≥ JFrog Artifactory versions before 7.29.3, < 7.29.3≥ JFrog Artifactory versions before 6.23.38, < 6.23.382022-03-02
CVE-2021-45074 [MEDIUM] CWE-284 CVE-2021-45074: JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privilege
JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.
cvelistv5nvd
CVE-2021-46270LOWCVSS 2.7≥ JFrog Artifactory versions before 7.31.10, < 7.31.102022-03-02
CVE-2021-46270 [LOW] CWE-284 CVE-2021-46270: JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user
JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.
cvelistv5nvd
CVE-2021-3860HIGHCVSS 8.8≥ JFrog Artifactory versions before 7.25.4 with E+ license, < 7.25.4≥ JFrog Artifactory versions before 6.23.30 with E+ license, < 6.23.302021-12-20
CVE-2021-3860 [HIGH] CWE-89 CVE-2021-3860: JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection
JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.
cvelistv5nvd