Artifactory Fixed Security Vulnerabilities

The section lists information about Artifactory security vulnerabilities that have been fixed in Artifactory.

CVEs Impacting Artifactory

The following is a list of CVEs that were discovered to impact Artifactory and were fixed.

CVESeverityArtifactory Fix Version(s)Fix Description
CVE-2025-24928High7.124.1Upgraded UBI base image to version to 9.6.1758184547
CVE-2025-22228Medium

CVE-2025-23083

CVE-2025-23084

CVE-2025-23085

High7.104.12Upgraded Node.js to version 22.14.0.
CVE-2024-22259High7.71.22Upgraded Spring to version 5.3.33 and Spring Security to version 5.8.11.
CVE-2024-23672High7.83.1Upgraded Apache Tomcat to version 9.0.87.
CVE-2024-25710High7.83.1Upgraded Apache commons to version 9.0.87.

CVE-2022-38751

CVE-2022-38752

Medium7.52.0Upgraded SnakeYAML to version 1.31.
CVE-2022-32213Critical7.41.7Upgraded Node.js to version 16.16.0.
CVE-2022-32214Critical7.41.7Upgraded Node.js to version 16.16.0.
CVE-2022-32215Critical7.41.7Upgraded Node.js to version 16.16.0.
CVE-2022-32223Critical7.41.7Upgraded Node.js to version 16.16.0.
CVE-2021-22573High7.41.4Upgraded the google-oauth-client to version 1.33.3.
CVE-2022-32212Critical7.39.10Upgraded Node.js to version 16.16.0.
CVE-2022-32213Critical7.39.10Upgraded Node.js to version 16.16.0.
CVE-2022-32214Critical7.39.10Upgraded Node.js to version 16.16.0.
CVE-2022-32215Critical7.39.10Upgraded Node.js to version 16.16.0.
CVE-2022-32223Critical7.39.10Upgraded Node.js to version 16.16.0.
CVE-2022-32212Critical7.38.16Upgraded Node.js to version 16.16.0.
CVE-2022-32213Critical7.38.16Upgraded Node.js to version 16.16.0.
CVE-2022-32214Critical7.38.16Upgraded Node.js to version 16.16.0.
CVE-2022-32215Critical7.38.16Upgraded Node.js to version 16.16.0.
CVE-2022-32223Critical7.38.16Upgraded Node.js to version 16.16.0.
CVE-2022-32212Critical7.37.17Upgraded Node.js to version 16.16.0.
CVE-2022-32213Critical7.37.17Upgraded Node.js to version 16.16.0.
CVE-2022-32214Critical7.37.17Upgraded Node.js to version 16.16.0.
CVE-2022-32215Critical7.37.18Upgraded Node.js to version 16.16.0.
CVE-2022-32223Critical7.37.17Upgraded Node.js to version 16.16.0.
CVE-2021-38561High7.37.13Upgraded internal/language/parse.go version 0.3.6 to version 0.3.7.
CVE-2021-41091Medium7.35.1

Upgraded to docker v20.10.9.

Upgraded image-spec v.1.0.2.

CVE-2021-3765High7.31.10Upgraded the validator version to 13.6.0.
CVE-2020-29582Medium

7.25.4

(Cloud)

Updated to the latest release of Koplin from version 1.3.50 to 1.5.20.
CVE-2019-20104High7.24.1Upgraded Crowd version to 3.7.2.
CVE-2020-14340Medium7.21.3Upgraded org.jboss.xnio:xnio-nio to version3.8.4.Final.
CVE-2021-25122High7.17.4Upgraded to Apache Tomcat version 8.5.63.
CVE-2019-10219Medium7.15.3Upgraded org.hibernate:hibernate-validator to version 6.0.18.
CVE-2017-18214High6.23.25npm moment.js library was upgraded to version 2.19.3.
CVE-2017-18640High6.23.0Upgraded snakeyaml-1.23.jar from version 1.26 to 1.27.
CVE-2020-7692Critical6.23.0Upgraded google-oauth-client library from version 1.27 to 1.31.
CVE-2019-12402Medium6.23.0Upgraded Commons-compress lib was upgraded to version 1.20.
CVE-2020-15586 and Go issue golang.org/issue/34902High6.23.0Upgraded to the latest version of Go 1.14.9.
CVE-2019-20104High6.23.0UpgradedCrowd lib to 3.7.2 version.
CVE-2018-1000206High6.1Artifactory now validates the actual value of the X-Request-With header instead of checking the existence of it.

Vulnerabilities Without a CVE Impacting Artifactory

The following is a list of vulnerabilities that do not have a CVE that impacted Artifactory and have been fixed.

DescriptionSeverityArtifactory Fix Version
Updated jackson-dataformats-binaryto version 2.12.3.High7.21.3
Excluded the Plexus-cipher library.Medium7.21.3
Upgraded om.nimbusds:oauth2-oidc-sdk:6.14 to 9.9.3.High7.21.3
Upgraded to wiremock-jre8 version 2.28.0.High7.21.3
Upgraded maven-shared-utils:3.2.1 to version 334.Critical7.21.3
Under certain circumstances, authenticated users were able to:
  • Retrieve environment information from Artifactory that normally required administrative rights.
  • Deploy binaries to Artifactory from different upstreams without having adequate permissions to perform these actions.
Critical6.13.3, 6.14.4, 6.15.2, 6.16.2, 6.17.1, 6.18.1, 7.3.2
Under certain circumstances, users could gain access to application data that should otherwise be exposed only to administrators.Critical6.8.14, 6.9.3, 6.10.4
Under certain circumstances, an unauthorized user may be able to send malformed REST API calls to Artifactory that execute under the identity of another user.Critical
  • 5.6.8, 5.7.3, 5.8.12, 5.9.8, 5.10.5, 5.11.5
  • 6.0.4, 6.1.4, 6.2.1, 6.3.4, 6.4.2, 6.5.9
A SAML-related authentication vulnerability potentially exposed Artifactory to XSW attacks which could sniff and manipulate SAML communications causing the incorrect verification of a SAML login response. This could potentially allow the attacker to gain access to any user in Artifactory.High6.5.13

CVEs Not Impacting Artifactory

The following is a list of CVEs that do not impact Artifactory.

CVESeverityArtifactory Fix VersionReason
CVE-2026-40976Critical7.146.10Artifactory is not affected because the findings are attributed to bundled side-car services, which have shipped fixes independently.
CVE-2026-5598CriticalTBDArtifactory is not affected because it does not use the vulnerable algorithm.
CVE-2026-29145Critical7.146.7According to JFrog assessment and tomcat report, this CVE is of Medium severity, not Critical.
CVE-2026-33815Critical7.133.18The latest versions of the affected package used by Artifactory are clear of vulnerabilities.
CVE-2026-33816Critical7.133.18The latest versions of the affected package used by Artifactory are clear of vulnerabilities.
CVE-2026-33186Critical7.133.17Artifactory is not affected because it does not use path filtering on grpc endpoints for authentication rules.
CVE-2026-22732High7.133.17Artifactory is not affected because it does not use Spring security to manage response headers for servlet applications
CVE-2025-41249High7.117.18Artifactory is not affected because it does not use the vulnerable code.
CVE-2025-7783HighTBDArtifactory is not affected because it does not use the vulnerable code.
CVE-2025-22874High7.117.1Artifactory is not affected because the vulnerable function Certificate.Verify is never called.
CVE-2022-48174Critical7.116.2Artifactory is not affected because the vulnerable package has been upgraded.
CVE-2025-31650High7.111.7. 7.114.2Artifactory is not affected because the vulnerable RewriteRule is never used.
CVE-2023-31484High7.111.4Does not affect Artifactory, since it only affects Postgres.
CVE-2025-22871MediumTBDArtifactory is not affected because the vulnerable function ListenAndServe is never called.
CVE-2025-24813Medium7.110.1Artifactory is not affected as it does not enable the Default Servlet.

CVE-2024-21208

CVE-2024-21210

CVE-2024-21211

CVE-2024-21217

CVE-2024-21235

MediumTBDAffected flow which includes loading data from external sources on runtime such as such as Java Applets or Web Start are not used in JFrog products.
CVE-2024-54677MediumTBDAffected system property sun.io.useCanonCachesis needs to be set to true for Artifactory to be affected. The value of this property is set to false by default and not changed by JFrog.
CVE-2024-56337HighTBDDefault servlet does not have a param-name named readonly set to false, which would be required for Artifactory to be affected.
CVE-2024-50379HighTBDWebapps/examples is not part of Artifactory deployment.

CVE-2021-38297

CVE-2022-23806

CVE-2023-24538

CVE-2023-24540

CVE-2023-29402

CVE-2023-29404

CVE-2023-29405

CVE-2024-24790

CVE-2025-21613

Critical7.104.2The Evidence service, which was not yet available to users, contained Go language vulnerabilities in the 7.98 release.

CVE-2023-23914

CVE-2021-27645

CVE-2021-33574

Normal / High7.102.0CVE exists in the Docker image and doesn't affect Artifactory.
CVE-2023-39332Critical7.102.0Flag required to leverage vulnerability (--experimental-permission) is not used the JFrog Platform.
CVE-2024-3651High7.102.0Does not affect Artifactory, since it only affects Postgres.
CVE-2024-52318Medium7.98.10Does not affect Artifactory because as JakartaServer Pages is not used.
CVE-2024-52316High7.98.10Does not affect Artifactory as the vulnerable components including Jakarta Authentication or any ServerAuthContext components are not used in its its authentication flow.
CVE-2024-47554High7.99.1Does not affect Artifactory as the vulnerable commons functionality is not in use.

CVE-2023-39325

CVE-2023-5156

CVE-2023-29409

CVE-2023-27536

Medium / High7.99.1CVE exists in the Docker image and doesn't affect Artifactory.
CVE-2024-45410Medium7.90.13The component using this functionality already forward those HTTP headers by design, hence this vulnerability didn't introduce any new behavior.

CVE-2021-28168

CVE-2020-36518

CVE-2021-46877

CVE-2022-2048

CVE-2022-42003

CVE-2022-42004

CVE-2023-36478

CVE-2023-44487

High7.95.0Does not affect Artifactory as the vulnerable functionality is not in use.
CVE-2024-39321High7.92.0Does not affect Artifactory is as it doesn't make use of the traefik IP filtering feature.
CVE-2023-44487Critical7.90.5Does not affect Artifactory as it only affects libnghttp
CVE-2023-29402Critical7.90.5Does not affect Artifactory as it only affects golang
CVE-2023-4016High7.90.5Does not affect Artifactory as it only affects go-pkgs
CVE-2023-32665High7.90.5Does not affect Artifactory as it only affects gLib
CVE-2023-32611High7.90.5Does not affect Artifactory as it only affects gLib
CVE-2023-29499High7.90.5Does not affect Artifactory as it only affects gLib
CVE-2023-29469High7.90.5Does not affect Artifactory as it only affects libxml2
CVE-2023-2602High7.90.5Does not affect Artifactory as it only affects libxml2
CVE-2021-38561High7.90.5Does not affect Artifactory as it only affects golang
CVE-2020-7919High7.90.5Does not affect Artifactory as it only affects golang
CVE-2019-11254High7.90.5Does not affect Artifactory as it only affects gopkg
CVE-2018-1099High7.90.5Does not affect Artifactory as it only affects gopkg
CVE-2023-39325High7.90.5Does not affect Artifactory as it only affects golang
CVE-2023-24539High7.90.5Does not affect Artifactory as it only affects golang
CVE-2023-29400High7.90.5Does not affect Artifactory as it only affects golang
CVE-2024-34750High7.91.1Does not impact Artifactory, as Artifactory does not use the vulnerable Apache Tomcat configuration.
CVE-2024-29857MediumN/ADoes not affect Artifactory, as Artifactory does not use the Bouncy Castle Java project in a vulnerable way.
CVE-2020-1712High7.86.0The CVE is present only in the docker image and does not affect Artifactory.
CVE-2024-1459High7.86.0Does not affect Artifactory, as it only affects undertow-core.
CVE-2024-28849Medium7.86.0Does not affect Artifactory, as it only affects Axios.
CVE-2022-1471Critical7.84.3Does not affect Artifactory, as the Artifactory usage of snakeyaml is not exploitable.
CVE-2024-26308High7.83.1Upgraded Apache commons to version 9.0.87.
CVE-2023-4586High7.81.1Does not affect Artifactory, as it only affects netty-handler.
CVE-2023-2976Medium7.81.1Does not affect Artifactory, as it only affects guava.
CVE-2024-21626High7.80.0Does not affect Artifactory, as it only affects runc.

CVE-2023-39325

CVE-2023-44487

High7.79.2Does not affect Artifactory, as it only affects golang.

CVE-2023-24539

CVE-2023-29400

High7.79.2Does not affect Artifactory, as it only affects golang.
CVE-2023-39323Critical7.76.0Does not affect Artifactory, as it only affects golang.
CVE-2023-6378High7.76.0Does not affect Artifactory, as it only affects logback-classic.
CVE-2023-44487High7.76.0Does not affect Artifactory, as it only affects golang.
CVE-2023-45857Medium7.75.0Does not affect Artifactory, as in the location where a vulnerable version of the Axios package is used, the vulnerability relates to a cookie but the communication is server-to-server (which doesn't use cookies).
CVE-2023-39325High7.71.5Does not affect Artifactory, as it only affects go.
CVE-2023-24540Critical7.71.2Does not affect Artifactory, as it only affects go.
CVE-2023-4759High7.71.2Does not affect Artifactory, as it only affects jgit.
CVE-2023-2253High7.71.2Does not affect Artifactory, as it only affects distribution.
CVE-2023-24540Critical7.70.2Does not affect Artifactory, as it only affects Golang.
CVE-2023-41080High7.68.11Does not affect Artifactory, as it only affects Apache Tomcat.
CVE-2023-29403High7.68.6Does not affect Artifactory, since it only affects yq.

CVE-2022-4450

CVE-2023-0215

High7.68.6Does not affect Artifactory, since it only affects openssl-libs.
CVE-2023-34035High7.68.6Does not affect Artifactory, since it only affects spring-security-config.
CVE-2023-2976Medium7.68.6Does not affect Artifactory, since it only affects guava.
CVE-2023-26136Critical7.66.3Does not affect Artifactory, since it only affects tough-cookie.
CVE-2023-29404Critical7.66.3Does not affect Artifactory, since it only affects golang.
CVE-2023-2976High7.66.3Does not affect Artifactory, since it only affects guava.
CVE-2023-35116High7.66.3Does not affect Artifactory, since it only affects jackson-databind.

CVE-2023-32731

CVE-2023-1428

CVE-2023-32732

High7.66.3Does not affect Artifactory, since it only affects grpc.
CVE-2023-26115Medium7.66.3Does not affect Artifactory, since it only affects word-wrap.
CVE-2022-25883Medium7.66.3Does not affect Artifactory, since it only affects semver.
CVE-2023-24539Medium7.66.3Does not affect Artifactory, since it only affects go.
CVE-2023-29401Medium7.66.3Does not affect Artifactory, since it only affects gin-gonic.
CVE-2023-29404Critical7.65.3Does not affect Artifactory, since it only affects golang.
CVE-2016-2510High7.65.3Does not affect Artifactory, since it only affects beanshell.
CVE-2023-26048Medium7.65.3Does not affect Artifactory, since it only affects jetty-server.
CVE-2023-1732Medium7.65.3Does not affect Artifactory, since it only affects circl.
CVE-2023-34462Medium7.65.3Does not affect Artifactory, since it only affects netty-handler.
CVE-2023-2976Medium7.65.3Does not affect Artifactory, since it only affects guava.
CVE-2022-25883Medium7.65.3Does not affect Artifactory, since it only affects semver.
CVE-2023-29404Critical7.64.4Does not impact Artifactory, since it only affects golang.
CVE-2023-29400High7.64.4Does not impact Artifactory, since it only affects golang.
CVE-2023-1732Medium7.64.4Does not impact Artifactory, since it only affects circl.
CVE-2023-2976Medium7.64.4Does not impact Artifactory, since it only affects guava.
CVE-2022-25883Medium7.64.4Does not impact Artifactory, since it only affects semver.
CVE-2023-28709High7.63.5Does not affect Artifactory, since it only impacts Apache Tomcat.
CVE-2023-20863High7.61.3Does not affect Artifactory, since it only impacts spring-core.
CVE-2022-41722High7.61.3Does not affect Artifactory, since it only impacts golangci-lint.
CVE-2023-27561High7.61.3Does not affect Artifactory, since it only impacts runc.
CVE-2023-0286High7.61.3Does not affect Artifactory, since it only impacts openssl-libs.

CVE-2022-25857

CVE-2022-41854

High7.61.3Does not affect Artifactory, since it only impacts snakeyaml.
CVE-2023-28708High7.61.3Does not affect Artifactory, since it only impacts apache tomcat.

CVE-2023-28642

CVE-2023-25809

Medium7.61.3Does not affect Artifactory, since it only impacts runc.

CVE-2023-28842

CVE-2023-28840

Medium7.61.3Does not affect Artifactory, since it only impacts docker.
CVE-2023-26125Medium7.61.3Does not affect Artifactory, since it only impacts gin-gonic.
CVE-2023-0845Medium7.61.3Does not affect Artifactory, since it only impacts hashicorp.
CVE-2023-1370High7.59.5Does not affect Artifactory, since it only affects json-smart.

CVE-2022-41722

CVE-2022-41725

CVE-2022-41724

High7.59.5Does not affect Artifactory, since it only affects Golang.
CVE-2022-41723High7.59.5Does not affect Artifactory, since it only affects Golang.
CVE-2022-25857High7.58.5Doesn't impact Artifactory, since it only affects SnakeYAML.
CVE-2022-41723High7.58.1Doesn't impact Artifactory, since it only affects Golang.
CVE-2022-43551High7.58.1Doesn't impact Artifactory, since it only affects curl.
CVE-2022-41717Medium7.58.1Doesn't impact Artifactory, since it only affects yq.
CVE-2022-41722High7.58.0Doesn't affect Artifactory, since it only affects Golang.
CVE-2022-41720High7.58.0Doesn't affect Artifactory, since it only affects Golang.
CVE-2022-41716High7.58.0Doesn't affect Artifactory, since it only affects Golang.
CVE-2022-2526High7.58.0Doesn't affect Artifactory, since it only affects systemd-libs.
CVE-2017-1000487Critical7.57.1Does not affect Artifactory, since it only affects plexus-utils.
CVE-2023-25173Medium7.57.1Does not affect Artifactory, since it only affects containerd.
CVE-2022-41716High7.56.2Does not affect Artifactory, since it only affects Golang.
CVE-2022-38900High7.56.2Does not affect Artifactory, since it only affects decode-uri-components.
CVE-2022-41720High7.56.2Does not affect Artifactory, since it only affects Golang.
CVE-2022-23471Medium7.56.2Does not affect Artifactory, since it only affects containerd.
CVE-2022-45143High7.55.1Does not affect Artifactory, since it only affects Apache Tomcat.
CVE-2022-42916High7.55.1Does not affect Artifactory, since it only affects curl.
CVE-2022-27664High7.55.1Does not affect Artifactory, since it only affects Golang.

CVE-2022-41716

CVE-2022-41715

CVE-2022-2880

CVE-2022-2879

High7.55.1Does not affect Artifactory, since it only affects Go.
CVE-2022-42004High7.55.1Does not affect Artifactory, since it only affects jackson-databind.
CVE-2022-42003High7.55.1Does not affect Artifactory, since it only affects jackson-databind.
CVE-2022-25857High7.55.1Does not affect Artifactory, since it only affects SnakeYAML.
CVE-2022-3171High7.55.1Does not affect Artifactory, since it only affects protobuf-java.
CVE-2022-41720High7.55.1Does not affect Artifactory, since it only affects Go.
CVE-2022-46175High7.55.1Does not affect Artifactory, since it only affects JSON5.
CVE-2021-26291Critical7.53.1Does not affect Artifactory, since it only affects Apache Maven.
CVE-2022-42898High7.53.1Does not affect Artifactory, since it only affects krb5-libs.
CVE-2022-32149High7.53.1Does not affect Artifactory, since it only affects Golang.

CVE-2022-23539

CVE-2022-23529

High7.53.1Does not affect Artifactory, since it only affects jsonwebtoken.
CVE-2022-4065High7.53.1Does not affect Artifactory, since it only affects testng.
CVE-2022-41716High7.53.1Does not affect Artifactory, since it only affects Golang.
CVE-2022-27664High7.53.1Does not affect Artifactory, since it only affects Golang.
CVE-2022-31030Medium7.53.1Does not affect Artifactory, since it only affects Containerd.
CVE-2022-41854Medium7.53.1Does not affect Artifactory, since it only affects SnakeYAML.
CVE-2022-45047Critical7.52.0Does not affect Artifactory, since it only affects Apache MINA SSHD.

CVE-2022-25857

CVE-2022-1471

High7.52.0Does not affect Artifactory, since it only affects SnakeYAML.
CVE-2022-1552High7.52.0Does not affect Artifactory, since it only affects Postgres.
CVE-2022-27664High7.52.0Does not affect Artifactory, since it only affects Golang.
CVE-2022-41720High7.52.0Does not affect Artifactory, since it only affects Golang.
CVE-2022-28948High7.52.0Does not affect Artifactory, since it only affects Go-yaml.
CVE-2021-33194High7.52.0Does not affect Artifactory, since it only affects golang.org/x/net.

CVE-2022-39271

GHSA-c6hx-pjc3-7fqr

High7.52.0Does not affect Artifactory, since it only affects traefik.
CVE-2022-31159High7.52.0Does not affect Artifactory, since it only affects aws-java-sdk.
CVE-2022-40716Medium7.52.0Does not affect Artifactory, since it only affects hashicorp.
CVE-2022-41915Medium7.52.0Does not affect Artifactory, since it only affects Netty.
CVE-2022-38749Medium7.52.0Does not affect Artifactory, since it only affects SnakeYAML and common.
CVE-2022-32190Critical7.50.3Does not affect Artifactory, since it only affects Go
CVE-2022-37866High7.50.3Doesn't affect Artifactory, since it only affects org.apache.ivy:ivy.
CVE-2022-31197High7.50.3Doesn't affect Artifactory, since it only affects org.postgresql:postgresql.

CVE-2016-5425

CVE-2016-6325

High7.50.3Doesn't affect Artifactory, since it only affects tomcat-jdbc.

CVE-2022-42003

CVE-2022-42004

High7.49.3Doesn't affect Artifactory, since it only affects java commons.
CVE-2022-25857High7.49.3Does not affect Artifactory, since it only affects Upgraded snakeyaml
CVE-2022-40151High7.49.3Does not affect Artifactory, since it only affects woodstox-core
CVE-2022-32149High7.49.3Does not affect Artifactory, since it only affects golang
CVE-2022-27664High7.49.3Does not affect Artifactory, since it only affects Go

GHSA-3mc7-4q67-w48m

GHSA-98wm-3w3q-mw94

GHSA-9w3m-gqgf-c4p9

GHSA-c4r9-r8fh-9vj2

GHSA-hhhw-99gj-p3c3

High7.49.3Does not affect Artifactory, since it only affects snakeyaml
CVE-2022-3171High7.49.3Does not affect Artifactory, since it only affects protobuf-java

CVE-2022-42003

CVE-2022-42004

GHSA-jjjh-jjxp-wpff

GHSA-rgv9-q543-rqg4

High7.49.3Does not affect Artifactory, since it only affects jackson-databind
CVE-2022-29526Medium7.49.3Does not affect Artifactory, since it only affects yq
CVE-2022-3171Medium7.49.3Does not affect Artifactory, since it only affects io.grpc::grpc-*
CVE-2022-36033Medium7.49.3Does not affect Artifactory, since it only affects jsoup
CVE-2022-38752Medium7.49.3Does not affect Artifactory, since it only affects commons
CVE-2022-1348Medium7.49.3Does not affect Artifactory, since it only affects logrotate

CVE-2019-20444

CVE-2019-20445

CVE-2019-16869

Critical7.47.7Does not affect Artifactory, since it only affectssoftware.amazon.awssdk:licensemanager.
CVE-2021-26291Critical7.47.7Does not affect Artifactory, since it only affects org.apache.maven.maven-project.

CVE-2022-1962

CVE-2022-28131

CVE-2022-30633

CVE-2022-30635

Critical7.47.7Does not affect Artifactory, since it only affects snakeyaml.
CVE-2021-44906High7.47.7Does not affect Artifactory, since it only affects grpc-tools.
CVE-2021-3807High7.47.7Does not affect Artifactory, since it only affects grpc-tools and grpc_tools_node_protoc_ts.
CVE-2022-25857High7.47.7Does not affect Artifactory, since it only affects snakeyaml.
CVE-2022-22970High7.46.3Does not affect Artifactory, since it only affects org.springframework:spring-beans.
CVE-2022-24823Medium7.47.7Does not affect Artifactory, since it only affects io.netty.
CVE-2020-7789Medium7.47.7

Does not affect Artifactory, since it only affects

grpc-tools and grpc_tools_node_protoc_ts.

CVE-2022-0235Medium7.47.7Does not affect Artifactory, since it only affects grpc-tools and grpc_tools_node_protoc_ts.
CVE-2022-30187Medium7.47.7Does not affect Artifactory, since it only affectsazure-storage-blob andv azure-core-http-okhttp.
CVE-2020-7608Medium7.47.7

Does not affect Artifactory, since it only affects grpc-tools and

grpc_tools_node_protoc_ts.

CVE-2022-25878Medium7.47.7

Does not affect Artifactory, since it only affects grpc-tools and

grpc_tools_node_protoc_ts.

CVE-2022-27191Medium7.47.7

Does not affect Artifactory, since it only affects grpc-tools and

http://grpc_tools_node_protoc_ts.golang.org/x/crypt.

CVE-2022-27191Medium7.46.3Does not affect Artifactory, since it only affects golang.org/x/crypto/ssh .
CVE-2022-31030Medium7.46.3Does not affect Artifactory, since it only affects containerd.
CVE-2022-22968Medium7.46.3Does not affect Artifactory, since it only affects org.springframework:spring-context.
CVE-2022-31197Medium7.46.3Does not affect Artifactory, since it only affects org.postgresql:postgresql.

CVE-2021-37136

CVE-2021-37137

Critical7.46.3Does not affect Artifactory, since it only affects io.netty:netty-codec:4.1.63.
CVE-2020-36518High7.46.3Does not affect Artifactory, since it only affects jackson-databind.
CVE-2022-22963Critical7.46.3Does not affect Artifactory, since it only affects spring-core5.3.18.
CVE-2022-2048High7.46.3Does not affect Artifactory, since it only affects org.eclipse.jetty.
CVE-2022-31159High7.46.3Does not affect Artifactory, since it only affects aws-java-sdk.
CVE-2021-3807High7.46.3Does not affect Artifactory, since it only affects jest-junitandansi-regex.
CVE-2020-28469High7.46.3Does not affect Artifactory, since it only affects glob-parent.
CVE-2021-20066Medium7.46.3Does not affect Artifactory, since it only affects jest.
CVE-2022-0235Medium7.46.3Does not affect Artifactory, since it only affects grpc-tools.
CVE-2020-7608Medium7.46.3Does not affect Artifactory, since it only affects yargs and yargs-parser.
CVE-2022-22950Medium7.46.3Does not affect Artifactory, since it only affects org.springframework:spring-expression.

CVE-2021-22096

CVE-2021-22060

Medium7.46.3Does not affect Artifactory, since it only affects org.spring framework:spring-core.
CVE-2022-24823Medium7.46.3Does not affect Artifactory, since it only affectsio.netty:netty-common.

CVE-2018-25031

CVE-2021-46708

Medium7.46.3Does not affect Artifactory, since it only affects com.github.tomakehurst:wiremock-jre8.
CVE-2021-43797Medium7.46.3Does not affect Artifactory, since it only affects io.netty:netty-codec-http.

CVE-2022-1962

CVE-2022-28131

CVE-2022-30633

CVE-2022-30635

Critical7.46.3Does not affect Artifactory, since it only affects github.com/golang/go.
CVE-2022-22971Critical7.42.1Does not affect Artifactory, since it only affects spring-core.
CVE-2020-36518High7.42.1Does not affect Artifactory, since it only affects fasterxml.jackson.version.
CVE-2020-36518High7.41.4Does not affect Artifactory, since it only affects jackson-databind.
CVE-2022-24823Medium7.41.4Does not affect Artifactory, since it only affects netty-common.
CVE-2021-3859High7.41.4Does not affect Artifactory, since it only affects Red Hat undertow-core.
CVE-2022-22963Critical7.41.4Does not affect Artifactory, since it only affectsspring-core.
CVE-2021-22119High7.41.4Does not affect Artifactory, since it only affectsspring-security-oauth2.
CVE-2022-23632Critical7.39.4Does not affect Artifactory, since it only affectsTraefik.
CVE-2022-29153High7.39.4Does not affect Artifactory, since it only affects consul.
CVE-2022-24769Medium7.39.4Does not affect Artifactory, since it only affectscontainerd.
CVE-2022-27191High7.39.4Does not affect Artifactory, since it only affectsgolang.org/x/crypto/ssh.
CVE-2022-23648High7.39.4Does not affect Artifactory, since it only affects to containerd.
CVE-2022-0536Medium7.39.4Does not affect Artifactory, since it only affects nodejs clients's axios.
CVE-2021-43797Medium7.37.13Does not affect Artifactory, since it only affects Netty.
CVE-2021-3807High7.37.13Does not affect Artifactory, since it only affects ansi-regex.
CVE-2022-23806Critical7.37.13Does not affect Artifactory, since it only affects Curve.IsOnCurve in crypto/elliptic in Go.
CVE-2021-41090Medium7.35.1Does not affect Artifactory, since it only affectsdocker and image-spec.
CVE-2021-22060Medium7.34.4Does not affect Artifactory, since it only affects org.springframework:spring-core:5.3.12.
CVE-2021-42550Medium7.31.10Does not affect Artifactory, since it only affects logback.xml.
CVE-2017-9506Medium7.31.10Does not affect Artifactory, since it only affects IconUriServlet of the Atlasssian OAuth Plugin.
CVE-2015-2575Medium7.31.10Does not affect Artifactory, since it only affects mysql:mysql-connector-java:8.0.20.
CVE-2021-42340High7.31.10

Does not affect Artifactory, since it only affects the Apache Tomcat versions:

9.0.48 and 8.5.73.

CVE-2020-13949High7.31.10Does not affect Artifactory, since it only affects the jaeger 1.6.0 which uses Thrift 0.14.1.

CVE-2021-35560

CVE-2021-35550

CVE-2021-35556

CVE-2021-35561

CVE-2021-35564

CVE-2021-35565

CVE-2021-35567

CVE-2021-35578

CVE-2021-35586

CVE-2021-35588

CVE-2021-35603

High7.31.10Does not affect Artifactory, since they only affect Java.
CVE-2021-36374Medium7.31.10Does not affect Artifactory, since it only affects theApache ant-1.9.15.
CVE-2021-33037Medium7.27.3Does not affect Artifactory, since it only affects the Apache Tomcat.
CVE-2021-22147High7.27.3Does not affect Artifactory, since it only affects theorg.elasticsearch:elasticsearch.
CVE-2021-22148High7.27.3Does not affect Artifactory, since it only affects theorg.elasticsearch:elasticsearch.
CVE-2021-22149High7.27.3Does not affect Artifactory, since it only affects theorg.elasticsearch:elasticsearch.
CVE-2021-30129High7.25.4Does not affect Artifactory, since it only affects the org.apache.sshd:sshd-core:2.6.0.
CVE-2017-18640High7.25.4Does not affect Artifactory, since it only affects the Snakeyaml 1.23 XML Entity Expansion.
CVE-2021-27568Critical7.25.4Does not affect Artifactory, since it only affects the json-smart-1.3.1.
CVE-2021-27568Critical7.25.4Does not affect Artifactory, since it only affects the json-smart-1.3.1.
CVE-2021-26291Normal7.24.1Does not affect Artifactory, since it only affects the Maven version 3.8.1.
CVE-2021-13936High7.24.1Does not affect Artifactory, since it only affects the Apache Velocity engine.
CVE-2018-9116Critical7.23.3Does not affect Artifactory, since it only affects wiremock.
CVE-2021-29505Critical7.21.3Does not affect Artifactory, since it only affects XStream.
CVE-2021-26291High7.21.3Does not affect Artifactory, since it only affects Apache Tomcat.
CVE-2021-21290Medium7.21.3Does not affect Artifactory, since it only affects netty-codec-http:4.1.53.final.
CVE-2020-17521Medium7.21.3Does not affect Artifactory, since it only affects org.codehaus.groovy:groovy-all.
CVE-2021-22112High7.17.4Does not affect Artifactory, since it only affects Spring Security Web.
CVE-2019-17571Medium7.15.3Does not affect Artifactory, since it only affects log4j-to-slf4j and log4j-api.
CVE-2016-10750High7.11.1Does not affect Artifactory, since it only affects hazelcast-3.6.1.jar
CVE-2017-7657Medium7.11.1Does not affect Artifactory, since it only affectsOrg.eclipse.jetty:jetty-http
CVE-2017-1000487High7.11.1Does not affect Artifactory, since it only affects Plexus-utils.
CVE-2020-25649High7.11.1Does not affect Artifactory, since it only affects fasterxml.jackson.version.
CVE-2019-17359High7.10.5Does not affect Artifactory, since it only affects bcprov-jdk15.
CVE-2020-7226High7.10.5Does not affect Artifactory, since it only affects at cryptacular-1.1.1.jar.
CVE-2020-7692Critical7.10.2Does not affect Artifactory, since it only affects google-oauth-client library.
CVE-2019-12402Medium7.10.1Does not affect Artifactory, since it only affects Commons-compress library.
CVE-2019-12402Medium7.10.1Does not affect Artifactory, since it only affects Commons-compress library.

CVE-2020-15586

golang.org/issue/34902

High7.10.1Does not affect Artifactory, since it only affects Go 1.14.9.
CVE-2019-20104High7.10.1Does not affect Artifactory, since it only affects Crowd lib.
CVE-2017-7957High7.10.1Does not affect Artifactory, since it only affects XStream.
CVE-2016-3674High7.10.1Does not affect Artifactory, since it only affects XStream.
CVE-2013-7285Critical7.10.1Does not affect Artifactory, since it only affects XStream.
CVE-2020-8203High7.9.0Does not affect Artifactory, since it only affects lodash.
CVE-2020-1745Critical7.9.0Does not affect Artifactory, since it only affects io.undertow:undertow-core / 2.0.15.Final.
CVE-2017-15095Critical7.8.1Does not affect Artifactory, since it only affects fge:jackson-coreutils:jar.
CVE-2017-17485Critical7.8.1Does not affect Artifactory, since it only affects fge:jackson-coreutils:jar.
CVE-2017-7525Critical7.8.1Does not affect Artifactory, since it only affects fge:jackson-coreutils:jar.
CVE-2020-13935High7.7.0Does not affect Artifactory, since it only affects Apache Tomcat.
CVE-2020-13934High7.7.0Does not affect Artifactory, since it only affects Apache Tomcat.
CVE-2020-11996High7.7.0Does not affect Artifactory, since it only affects Apache Tomcat.

CVE-2020-28500

CVE-2020-8203

CVE-2021-23337

Critical6.23.25Does not affect Artifactory, since it only affects npm lodash library
CVE-2022-46337HighN/A

Does not affect Artifactory, as it only affects derby.

While the usage of the vulnerable version of derby is found, it is not exploitable because it requires administrative access to the machine and the attributes in system.yaml. Furthermore, the usage of the Derby database isn’t intended for production setups, it is used as a local database mostly for testing and small-scale installations.

CVE-2022-42252HighN/ADoes not affect Artifactory, since it only affects Apache Tomcat.
CVE-2022-30591HighN/AJFrog Artifactory is not affected, since it does not use the quic-go through 0.27.0.
CVE-2022-42889CriticalN/AJFrog Platformis not affected, since it does not use the impacted packages.
CVE-2016-1000027CriticalN/ADoes not affect Artifactory, since it does not use the impacted HttpInvokerServiceExporter component for providing remote access.
CVE-2022-34305MediumN/ADoes not affect Artifactory, since it does not use the impacted component that is included in the Apache Tomcat version.
CVE-2022-29885HighN/ADoes not affect Artifactory, since it does not use the impacted component that is included in the Apache Tomcat version.
CVE-2018-10892HighN/ADoes not affect Artifactory, since only Traefik uses it, and thereby applies only if the Docker Provider is turned on, which is not the case in Artifactory.
CVE-2020-0187MediumN/ADoes not affect Artifactory, since it only affects the Android Platform.
CVE-2020-0187MediumN/ADoes not affect Artifactory, since it only affects the Android Platform.
N/AMediumN/ADoes not affect Artifactory, as it applies only when using Apache Sling which is not the case in Artifactory.
N/AMediumN/ADoes not affect Artifactory, since it only affects SSLServerSocketAppender and {{SSLSocketAppender}}
CVE-2017-7536HighN/ADoes not affect Artifactory, since Artifactory is not using org.hibernate_hibernate-validator.
CVE-2020-9484HighN/ADoes not affect Artifactory, since the vulnerability is exploitable in case Tomcat is configured with PersistenceManager, which Artifactory does not use.
CVE-2019-11888HighN/AThis CVE supposedly affects Artifactory 6.x versions. The golang/go library is part of the Metadata Service which is not enabled in Artifactory 6.x version.
CVE-2019-14809HighN/AThis CVE supposedly affects Artifactory 6.x versions. The golang/go library is part of the Metadata Service which is not enabled in Artifactory 6.x version.
CVE-2019-0232HighN/AThe enableCmdLineArguments parameter is not enabled in the Apache Tomcat bundled with Artifactory.
CVE-2018-8014HighN/AThe JFrog Apache Tomcat version is 8.5.32, which is not one of the vulnerable versions.
CVE-2018-1275HighN/AThe JFrog Spring Framework version is 4.1.8, which is vulnerable to the CVE, as the version is unsupported. However, because JFrog does not implement STOMP broker, we are not exposed to this vulnerability
CVE-2018-8589MediumN/AJFrog is not responsible for vulnerabilities in the Windows operating system. Anyone using an on-premises environment should keep the Windows operating system up to date.
CVE-2018-11776HighN/ADoes not affect Artifactory, since JFrog does not use Apache Struts.
CVE-2018-5925HighN/ADoes not affect Artifactory, since the issue relates to certain HP Inkjet printers and is not relevant to JFrog.
CVE-2018-5924HighN/ADoes not affect Artifactory, since the issue relates to certain HP Inkjet printers and is not relevant to JFrog.
CVE-2018-5382HighN/ADoes not affect Artifactory, since JFrog does not use BKS-V1 keystore.
CVE-2018-1260HighN/ADoes not affect Artifactory, since JFrog does not use Spring Security Oauth.
CVE-2018-1259HighN/ADoes not affect Artifactory, since JFrog does not use Spring Data Commons.
CVE-2017-5664HighN/ADoes not affect Artifactory, since the default value for the readOnly property in the DefaultServlet is "true" (readOnly=true) in our environment. As mentioned in the CVE, you are only vulnerable: "...if the DefaultServlet is configured to permit writes..."
CVE-2017-5648CriticalN/ADoes not affect Artifactory, since the the tomcat/webapps folder only contains the Artifactory WAR and the Access WAR files used by the bundled Tomcat distribution.
CVE-2017-5647HighN/ADoes not affect Artifactory, since the issue refers/relates only to the "Send File" service which is not used by Artifactory.
CVE-2017-5638CriticalN/AArtifactory is not affected by the Apache Struts 2 vulnerability.
CVE-2014-0097HighN/A

For LDAP authentication, Artifactory strictly uses the ArtifactoryLdapAuthenticationProvider class that uses the ArtifactoryLdapAuthenticator, wrapping the ArtifactoryBindAuthenticator. The latter class is the one used to perform the actual authentication and it does check for empty passwords.

Artifactory does not use any other provider with LDAP, such as ActiveDirectoryLdapAuthenticationProvider. This JIRA issue refers to an older class name, ActiveDirectoryLdapAuthenticator, that is not part of Spring Security and Artifactory.

CVE-2008-4108HighN/ADoes not affect Artifactory, since Artifactory Jfrog does not require Python to be installed; the CVE is not relevant for Jfrog.
CVE-2005-2541HighN/ADoes not affect Artifactory, since Artifactory uses Tar 1.30.1.

Did this page help you?