Artifactory
by Jfrog
Source repositories
CVEs (73)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-69107 | Med | 0.38 | 5.9 | 0.00 | Aug 12, 2026 | An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. | ||
| CVE-2022-0668 | Med | 0.35 | 5.3 | 0.01 | Jan 8, 2023 | JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user. | ||
| CVE-2019-10324 | Med | 0.35 | 6.5 | 0.01 | May 31, 2019 | A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform… | ||
| CVE-2026-68760 | Med | 0.34 | 5.3 | 0.00 | Aug 12, 2026 | An unauthenticated user may bypass authentication under specific cache conditions. | ||
| CVE-2026-68753 | Med | 0.34 | 5.3 | 0.00 | Aug 12, 2026 | An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | ||
| CVE-2021-41834 | Med | 0.34 | 5.3 | 0.01 | May 23, 2022 | JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation. | ||
| CVE-2025-14830 | Med | 0.32 | 4.9 | 0.00 | Jan 4, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artifactory (Workers) allows Cross-Site Scripting (XSS).This issue affects Artifactory (Workers): from >=7.94.0 through <7.117.10. | ||
| CVE-2021-46687 | Med | 0.32 | 4.9 | 0.01 | Jul 6, 2022 | JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions… | ||
| CVE-2026-70547 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2026 | An authenticated user without repository read permission may access package metadata under specific conditions. | ||
| CVE-2026-66382 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2026 | An authenticated user may write files outside the intended Artifactory work directory under specific conditions. | ||
| CVE-2026-66380 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2026 | An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | ||
| CVE-2026-66379 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2026 | An authenticated user may view private Puppet module metadata without repository read access. | ||
| CVE-2026-66378 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2026 | An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | ||
| CVE-2024-3505 | Med | 0.28 | 4.3 | 0.00 | Apr 15, 2024 | JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments. | ||
| CVE-2021-45074 | Med | 0.28 | 4.3 | 0.01 | Mar 2, 2022 | JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session. | ||
| CVE-2019-10323 | Med | 0.28 | 4.3 | 0.02 | May 31, 2019 | A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. | ||
| CVE-2019-10322 | Med | 0.28 | 4.3 | 0.02 | May 31, 2019 | A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another… | ||
| CVE-2019-10321 | Med | 0.28 | 4.3 | 0.01 | May 31, 2019 | A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained… | ||
| CVE-2026-70548 | Low | 0.23 | 3.5 | 0.00 | Aug 25, 2026 | Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency. | ||
| CVE-2026-65926 | Low | 0.20 | 3.1 | 0.00 | Aug 12, 2026 | An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known. |
- risk 0.38cvss 5.9epss 0.00
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
- risk 0.35cvss 5.3epss 0.01
JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.
- risk 0.35cvss 6.5epss 0.01
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform…
- risk 0.34cvss 5.3epss 0.00
An unauthenticated user may bypass authentication under specific cache conditions.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
- risk 0.34cvss 5.3epss 0.01
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.
- risk 0.32cvss 4.9epss 0.00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artifactory (Workers) allows Cross-Site Scripting (XSS).This issue affects Artifactory (Workers): from >=7.94.0 through <7.117.10.
- risk 0.32cvss 4.9epss 0.01
JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions…
- risk 0.28cvss 4.3epss 0.00
An authenticated user without repository read permission may access package metadata under specific conditions.
- risk 0.28cvss 4.3epss 0.00
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
- risk 0.28cvss 4.3epss 0.00
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.
- risk 0.28cvss 4.3epss 0.00
An authenticated user may view private Puppet module metadata without repository read access.
- risk 0.28cvss 4.3epss 0.00
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
- risk 0.28cvss 4.3epss 0.00
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.
- risk 0.28cvss 4.3epss 0.01
JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.
- risk 0.28cvss 4.3epss 0.02
A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
- risk 0.28cvss 4.3epss 0.02
A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another…
- risk 0.28cvss 4.3epss 0.01
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained…
- risk 0.23cvss 3.5epss 0.00
Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.
- risk 0.20cvss 3.1epss 0.00
An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.
Page 3 of 4