Vulnerabilities
Vulnerable Software
Jfrog:  >> Artifactory  >> 2.2.7  Security Vulnerabilities
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
CVSS Score
5.3
EPSS Score
0.003
Published
2026-08-12
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
CVSS Score
4.3
EPSS Score
0.003
Published
2026-08-12
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
CVSS Score
8.1
EPSS Score
0.003
Published
2026-08-12
Credentials for a deleted user may remain valid for a short period under specific conditions.
CVSS Score
4.2
EPSS Score
0.002
Published
2026-08-12
An unauthenticated user may access restricted repository information under specific conditions.
CVSS Score
5.3
EPSS Score
0.003
Published
2026-08-12
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-08-12
An authenticated user may view private Puppet module metadata without repository read access.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-08-12
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-08-12
Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
CVSS Score
6.5
EPSS Score
0.008
Published
2020-03-25
Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
CVSS Score
7.5
EPSS Score
0.011
Published
2020-03-25


Contact Us

Shodan ® - All rights reserved