VendorsJFrogartifactoryall versions
Vulnerabilities

JFrog Artifactory

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

70CVEs
CVE-2019-10324
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven projects, and promote previously staged builds, respectively.
Published 2019-05-31 · Modified
6.5EPSS 0.007
CVE-2021-41834
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.
Published 2022-05-23 · Modified
6.5EPSS 0.006
CVE-2026-65924
Server-Side Request Forgery (SSRF) via Terraform Remote repository
Published 2026-07-27 · Analyzed
6.5EPSS 0.004
CVE-2023-42508
JFrog Artifactory Improper header input validation leads to email manipulation sent from the platform
Published 2023-10-03 · Modified
6.5EPSS 0.004
CVE-2026-66018
JFrog Artifactory build environment properties exposure
Published 2026-07-27 · Analyzed
6.5EPSS 0.004
CVE-2026-65618
Improper URL validation when handling specific URLs Pub, Terraform and Docker packages might lead to SSRF vulnerability
Published 2026-07-27 · Analyzed
6.5EPSS 0.004
CVE-2026-68758
Authenticated users may access restricted Artifactory support information
Published 2026-08-12 · Analyzed
6.5EPSS 0.004
CVE-2026-65925
Server-Side Request Forgery (SSRF) via JFrog Artifactory Cargo remote repository
Published 2026-07-27 · Analyzed
6.5EPSS 0.004
CVE-2026-68754
Publishers without delete permission can overwrite docker layer information
Published 2026-08-12 · Analyzed
6.5EPSS 0.003
CVE-2021-45721
JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before 6.23.41 versions prior to 6.23.38.
Published 2022-07-06 · Modified
6.1EPSS 0.006
CVE-2021-45730
JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.
Published 2022-05-19 · Modified
6.0EPSS 0.005
CVE-2026-69107
Potential unauthorized artifact access in JFrog Artifactory
Published 2026-08-12 · Analyzed
5.9EPSS 0.004
CVE-2021-45074
JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.
Published 2022-03-02 · Modified
5.5EPSS 0.006
CVE-2026-66376
Deleted users may temporarily retain access to JFrog Artifactory
Published 2026-08-12 · Analyzed
5.4EPSS 0.002
CVE-2026-66384
Authenticated users may write data outside the intended Docker cache path
Published 2026-08-12 · Analyzed
5.3KEVEPSS 0.007
CVE-2026-68760
Potential remember-me authentication bypass in JFrog Artifactory
Published 2026-08-12 · Analyzed
5.3EPSS 0.005
CVE-2026-66381
Repository readers may access content outside configured upstream paths
Published 2026-08-12 · Analyzed
5.3EPSS 0.004
CVE-2026-66377
Anonymous users may access restricted Artifactory repository information
Published 2026-08-12 · Analyzed
5.3EPSS 0.004
CVE-2026-68753
Anonymous users may access restricted Artifactory content under specific configurations
Published 2026-08-12 · Analyzed
5.3EPSS 0.003
CVE-2019-10323
A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
Published 2019-05-31 · Modified
4.3EPSS 0.018
CVE-2019-10322
A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Published 2019-05-31 · Modified
4.3EPSS 0.018
CVE-2019-10321
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Published 2019-05-31 · Modified
4.3EPSS 0.008
CVE-2024-3505
JFrog Self-Hosted Artifactory Proxy configuration accessible to low-privilege users
Published 2024-04-15 · Analyzed
4.3EPSS 0.004
CVE-2026-66382
Authenticated users may write files outside the intended Artifactory work directory
Published 2026-08-12 · Analyzed
4.3EPSS 0.004
CVE-2026-66380
Authenticated users may access private OCI referrer metadata
Published 2026-08-12 · Analyzed
4.3EPSS 0.003
CVE-2026-66379
Authenticated users may view private Puppet module metadata
Published 2026-08-12 · Analyzed
4.3EPSS 0.003
CVE-2026-66378
Authenticated users may access private NuGet metadata
Published 2026-08-12 · Analyzed
4.3EPSS 0.003
CVE-2026-70547
Potential unauthorized metadata exposure in JFrog Artifactory
Published 2026-08-12 · Analyzed
4.3EPSS 0.003
CVE-2026-68755
Bundle writers may alter trusted release information in JFrog Artifactory
Published 2026-08-12 · Analyzed
4.3EPSS 0.003
CVE-2021-46270
JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.
Published 2022-03-02 · Modified
4.0EPSS 0.006
← Prev2 / 2