Vulnerabilities
Vulnerable Software
Jfrog:  >> Artifactory  >> 6.23.42  Security Vulnerabilities
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
CVSS Score
8.8
EPSS Score
0.007
Published
2026-07-27
CVE-2026-42016
Known exploited
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CVSS Score
8.1
EPSS Score
0.091
Published
2026-07-27
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.
CVSS Score
8.8
EPSS Score
0.003
Published
2026-07-27
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.
CVSS Score
4.3
EPSS Score
0.004
Published
2024-04-15
JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.
CVSS Score
8.8
EPSS Score
0.005
Published
2024-03-13
JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.
CVSS Score
7.2
EPSS Score
0.009
Published
2024-03-07


Contact Us

Shodan ® - All rights reserved