JFrog develops a focused but widely deployed software artifact repository and release automation platform, Artifactory, that serves as a critical supply-chain node in many enterprise build and deployment pipelines. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and a moderate tendency toward public exploit availability reflecting the platform's high-value and internet-exposed operational role. The exposure recurs through weakness classes including improper access control, cross-site request forgery, and input-validation flaws that are characteristic of web-based repository and integration platforms where authentication, session management, and data-handling logic are central attack surfaces. Defenders should prioritize patching this vendor's advisories given the platform's position in software delivery chains and the access it grants to build artifacts and credentials. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by JFrog over time
Of all the CVEs published by JFrog as a CNA, 16.0% affect products that JFrog develops as a vendor.
Of all the CVEs published that affect products developed by JFrog, 54.3% are self-published by JFrog as a CNA.
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17444CRITICAL Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attac | Oct 12, 2020 | 9.8 | 79 | NO | YES |
CVE-2019-9733CRITICAL An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out | Apr 11, 2019 | 9.8 | 66 | NO | YES |
CVE-2016-10036CRITICAL Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arb | May 1, 2018 | 9.8 | 47 | NO | YES |
CVE-2018-19971CRITICAL JFrog Artifactory Pro 6.5.9 has Incorrect Access Control. | Apr 16, 2019 | 9.8 | 32 | NO | NO |
CVE-2016-6501CRITICAL JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning. | Dec 9, 2016 | 9.8 | 32 | NO | NO |
CVE-2022-0668CRITICAL JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated use | Jan 8, 2023 | 9.8 | 31 | NO | NO |
CVE-2024-6915CRITICAL JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to ca | Aug 5, 2024 | 9.3 | 30 | NO | NO |
CVE-2021-23163HIGH JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog | Jul 6, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-3860HIGH JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when perfor | Dec 20, 2021 | 8.8 | 28 | NO | NO |
CVE-2024-4142CRITICAL An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory.
Due to this vulnerability, users with low privi | May 1, 2024 | 9.0 | 26 | NO | NO |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by JFrog.
Media articles that mention a CVE ID that affects a product developed by JFrog — matched by CVE ID, not by vendor name.