JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration.
This does not affect JFrog cloud deployments.
References
| Link | Resource |
|---|---|
| https://jfrog.com/help/r/jfrog-release-information/jfrog-security-advisories | Vendor Advisory |
| https://jfrog.com/help/r/jfrog-release-information/jfrog-security-advisories | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-04-15 08:15
Updated : 2025-04-01 13:59
NVD link : CVE-2024-3505
Mitre link : CVE-2024-3505
CVE.ORG link : CVE-2024-3505
JSON object : View
Products Affected
jfrog
- artifactory
CWE
