PT-2024-26298 · Jfrog · Jfrog Artifactory

CVE-2024-3505

·

Published

2024-04-15

·

Updated

2025-04-02

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions JFrog Artifactory Self-Hosted versions prior to 7.77.3
Description The issue allows a low-privileged authenticated user to disclose sensitive information by reading the proxy configuration. This does not affect JFrog cloud deployments.
Recommendations For versions prior to 7.77.3, update to version 7.77.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the proxy configuration to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ARTIFACTORY-2024-3505
CVE-2024-3505

Affected Products

Jfrog Artifactory