Vulnerabilities
Vulnerable Software
Jfrog:  >> Artifactory  >> 2.1.1  Security Vulnerabilities
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
CVSS Score
8.8
EPSS Score
0.007
Published
2026-07-27
CVE-2026-42016
Known exploited
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CVSS Score
8.1
EPSS Score
0.091
Published
2026-07-27
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.
CVSS Score
8.8
EPSS Score
0.003
Published
2026-07-27
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.
CVSS Score
4.3
EPSS Score
0.004
Published
2024-04-15
JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.
CVSS Score
8.8
EPSS Score
0.005
Published
2024-03-13
JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.
CVSS Score
7.2
EPSS Score
0.009
Published
2024-03-07
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.
CVSS Score
5.3
EPSS Score
0.006
Published
2022-05-23
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.
CVSS Score
9.8
EPSS Score
0.694
Published
2020-10-12
Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
CVSS Score
6.5
EPSS Score
0.008
Published
2020-03-25
Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
CVSS Score
7.5
EPSS Score
0.011
Published
2020-03-25


Contact Us

Shodan ® - All rights reserved