VYPR

Artifactory

by Jfrog

Source repositories

CVEs (73)

  • CVE-2026-69107MedAug 12, 2026
    risk 0.38cvss 5.9epss 0.00

    An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

  • CVE-2022-0668MedJan 8, 2023
    risk 0.35cvss 5.3epss 0.01

    JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.

  • CVE-2019-10324MedMay 31, 2019
    risk 0.35cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform…

  • CVE-2026-68760MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated user may bypass authentication under specific cache conditions.

  • CVE-2026-68753MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.

  • CVE-2021-41834MedMay 23, 2022
    risk 0.34cvss 5.3epss 0.01

    JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.

  • CVE-2025-14830MedJan 4, 2026
    risk 0.32cvss 4.9epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artifactory (Workers) allows Cross-Site Scripting (XSS).This issue affects Artifactory (Workers): from >=7.94.0 through <7.117.10.

  • CVE-2021-46687MedJul 6, 2022
    risk 0.32cvss 4.9epss 0.01

    JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions…

  • CVE-2026-70547MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user without repository read permission may access package metadata under specific conditions.

  • CVE-2026-66382MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user may write files outside the intended Artifactory work directory under specific conditions.

  • CVE-2026-66380MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.

  • CVE-2026-66379MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user may view private Puppet module metadata without repository read access.

  • CVE-2026-66378MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user without repository read permission may access private NuGet metadata under specific conditions.

  • CVE-2024-3505MedApr 15, 2024
    risk 0.28cvss 4.3epss 0.00

    JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.

  • CVE-2021-45074MedMar 2, 2022
    risk 0.28cvss 4.3epss 0.01

    JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.

  • CVE-2019-10323MedMay 31, 2019
    risk 0.28cvss 4.3epss 0.02

    A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2019-10322MedMay 31, 2019
    risk 0.28cvss 4.3epss 0.02

    A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another…

  • CVE-2019-10321MedMay 31, 2019
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained…

  • CVE-2026-70548LowAug 25, 2026
    risk 0.23cvss 3.5epss 0.00

    Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.

  • CVE-2026-65926LowAug 12, 2026
    risk 0.20cvss 3.1epss 0.00

    An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.