Skip to main content

Vendor archive

jfrog CVEs

Beta · best-effort

45 CVEs tagged to vendor jfrog6 Critical, 18 High, 19 Medium, 2 Low, 0 Unrated.

CVE-2022-0573

Published May 16, 2022

JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-46270

Published Mar 2, 2022

JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission v…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-45074

Published Mar 2, 2022

JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reau…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3860

Published Dec 20, 2021

JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when perfo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17444

Published Oct 12, 2020

Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based atta…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-2165

Published Mar 25, 2020

Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2164

Published Mar 25, 2020

Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by us…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19937

Published Mar 16, 2020

In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7931

Published Jan 23, 2020

In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10324

Published May 31, 2019

A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doSta…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10323

Published May 31, 2019

A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credenti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10322

Published May 31, 2019

A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10321

Published May 31, 2019

A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read ac…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9733

Published Apr 11, 2019

An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked ou…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000424

Published Jan 9, 2019

An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attack…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000206

Published Jul 13, 2018

JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF attack allowing an attacker to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000623

Published Jul 9, 2018

JFrog JFrog Artifactory version Prior to version 6.0.3, since version 4.0.0 contains a Directory Traversal vulnerability in The "Import Repository from Zip" feature, available thr…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10036

Published May 1, 2018

Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute ar…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6501

Published Dec 9, 2016

JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 26-45 of 45 CVEsPage 2 of 2