| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. |
| JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. |
| JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. |
| A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. |
| Credentials for a deleted user may remain valid for a short period under specific conditions. |
| An unauthenticated user may access restricted repository information under specific conditions. |
| An authenticated user without repository read permission may access private NuGet metadata under specific conditions. |
| An authenticated user may view private Puppet module metadata without repository read access. |
| An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. |
| A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. |
| An authenticated user may write files outside the intended Artifactory work directory under specific conditions. |
| A Project Resource Manager may gain broader administrative privileges under specific conditions. |
| An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. |
| A repository publisher without delete permission may modify protected package content under specific conditions. |
| A bundle writer may create misleading release promotion information under specific conditions. |
| A party with write access to stored session data may affect JFrog Artifactory under specific conditions. |
| A user with access to a valid SAML response may impersonate another user under specific conditions. |
| An unauthenticated user may bypass authentication under specific cache conditions. |
| A low-privileged authenticated user may access restricted support information under specific conditions. |
| A holder of a valid integration credential may impersonate other users under specific conditions. |