Artifactory
Vendor:
First CVE: Dec 9, 2016 · Active for 9 years
35
Total CVEs
More Total CVEs than 96% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Artifactory over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 9, 2016
9 years ago
Most Recent CVE
Aug 5, 2024
720 days ago
CVE Severity & Scoring
Artifactory35 CVEs
43%
31%
23%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.9%)
Network34 (97.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (94.3%)
High2 (5.7%)
Unknown0 (0.0%)
User Interaction
None26 (74.3%)
Unknown0 (0.0%)
Required9 (25.7%)
Privileges Required
Low11 (31.4%)
High5 (14.3%)
None19 (54.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17444CRITICAL Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attac | Oct 12, 2020 | 9.8 | 79 | NO | YES |
CVE-2019-9733CRITICAL An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out | Apr 11, 2019 | 9.8 | 66 | NO | YES |
CVE-2016-10036CRITICAL Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arb | May 1, 2018 | 9.8 | 47 | NO | YES |
CVE-2018-19971CRITICAL JFrog Artifactory Pro 6.5.9 has Incorrect Access Control. | Apr 16, 2019 | 9.8 | 32 | NO | NO |
CVE-2016-6501CRITICAL JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning. | Dec 9, 2016 | 9.8 | 32 | NO | NO |
CVE-2022-0668CRITICAL JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated use | Jan 8, 2023 | 9.8 | 31 | NO | NO |
CVE-2024-6915CRITICAL JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to ca | Aug 5, 2024 | 9.3 | 30 | NO | NO |
CVE-2021-23163HIGH JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog | Jul 6, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-3860HIGH JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when perfor | Dec 20, 2021 | 8.8 | 28 | NO | NO |
CVE-2024-4142CRITICAL An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory.
Due to this vulnerability, users with low privi | May 1, 2024 | 9.0 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (35 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
5.7% of CVEs· 97th percentile
ExploitDB
1 CVE
2.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (35 CVEs).
Media Mentions
Signals from CVEs in this product scope (35 CVEs).
Top CNAs Publishing CVEs For Artifactory
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.36.0 | 1 | 8.8 | 1.9% | 0 | 0 |
| 7.35.0 | 1 | 8.8 | 1.9% | 0 | 0 |
| 6.7.3 | 1 | 9.8 | 53.9% | 0 | 1 |
| 6.5.9 | 1 | 9.8 | 3.0% | 0 | 0 |