CVE-2023-42509
- EPSS 0.44%
- Veröffentlicht 07.03.2024 14:15:46
- Zuletzt bearbeitet 11.03.2025 16:57:11
JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.
CVE-2023-42662
- EPSS 0.48%
- Veröffentlicht 07.03.2024 09:15:38
- Zuletzt bearbeitet 11.03.2025 16:40:52
JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / ...
CVE-2023-42508
- EPSS 0.41%
- Veröffentlicht 03.10.2023 13:15:11
- Zuletzt bearbeitet 21.11.2024 08:22:41
JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body.
CVE-2022-0668
- EPSS 0.63%
- Veröffentlicht 08.01.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:39:08
JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.
CVE-2021-23163
- EPSS 0.34%
- Veröffentlicht 06.07.2022 10:15:09
- Zuletzt bearbeitet 21.11.2024 05:51:18
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artif...
CVE-2021-45721
- EPSS 0.54%
- Veröffentlicht 06.07.2022 10:15:09
- Zuletzt bearbeitet 21.11.2024 06:32:58
JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7....
CVE-2021-46687
- EPSS 0.78%
- Veröffentlicht 06.07.2022 10:15:09
- Zuletzt bearbeitet 21.11.2024 06:34:35
JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; J...
CVE-2021-41834
- EPSS 0.56%
- Veröffentlicht 23.05.2022 07:16:13
- Zuletzt bearbeitet 21.11.2024 06:26:50
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permiss...
CVE-2021-45730
- EPSS 0.53%
- Veröffentlicht 19.05.2022 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:58
JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.
CVE-2022-0573
- EPSS 1.99%
- Veröffentlicht 16.05.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:56
JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated ...