VYPR

Artifactory Self-Hosted

by Jfrog

CVEs (2)

  • CVE-2026-42016HigKEVJul 27, 2026
    risk 0.65cvss 8.1epss 0.09

    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

  • CVE-2024-3505MedApr 15, 2024
    risk 0.28cvss 4.3epss 0.00

    JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.